First published: Tue Jan 21 2020(Updated: )
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift | =3.11 | |
Redhat Openshift | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this insecure modification vulnerability in /etc/passwd file is CVE-2019-19350.
The severity level of CVE-2019-19350 is high with a CVSS score of 7.8.
CVE-2019-19350 affects Red Hat Openshift 4 and 3.11.
An attacker with access to the container could exploit CVE-2019-19350 to modify the /etc/passwd file and escalate their privileges.
Yes, you can find references for CVE-2019-19350 at the following links: [Bugzilla Red Hat - CVE-2019-19350](https://bugzilla.redhat.com/show_bug.cgi?id=1791534), [Bugzilla Red Hat - CVE-2019-19350](https://bugzilla.redhat.com/show_bug.cgi?id=1793283), [Bugzilla Red Hat - CVE-2019-19350](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1791534)