CVE-2019-19348: High severity red hat openshift vulnerability
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Other sources
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/apb-base-container.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-19348?
CVE-2019-19348 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2019-19348?
To fix CVE-2019-19348, upgrade to openshift-enterprise-apb-base-container version 4.3.5 or later, 4.2.21 or later, 4.1.37 or later, or 3.11.188-4.
What versions of OpenShift are affected by CVE-2019-19348?
CVE-2019-19348 affects OpenShift versions before 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4.
Who can exploit CVE-2019-19348?
An attacker with access to the affected OpenShift container can exploit CVE-2019-19348 to modify the /etc/passwd file.
What is the impact of CVE-2019-19348?
The impact of CVE-2019-19348 includes the potential for an attacker to gain elevated privileges within the container.