CVE-2019-19353: High severity red hat openshift container platform vulnerability
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Other sources
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/hive-container.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19353?
CVE-2019-19353 is considered a critical vulnerability due to its potential to allow privilege escalation.
How does CVE-2019-19353 affect Red Hat OpenShift Container Platform 4.0?
CVE-2019-19353 allows an attacker with container access to modify the /etc/passwd file, leading to serious security risks.
What are the potential impacts of exploiting CVE-2019-19353?
Exploiting CVE-2019-19353 can lead to unauthorized privilege escalation, allowing attackers to gain elevated access to the system.
How do I fix CVE-2019-19353?
To fix CVE-2019-19353, apply the latest security updates provided by Red Hat for OpenShift Container Platform.
Can CVE-2019-19353 be mitigated?
Mitigation of CVE-2019-19353 involves restricting container access and monitoring for suspicious modifications to critical files like /etc/passwd.