CVE-2019-19354: High severity red hat openshift container platform vulnerability
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Other sources
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/hadoop-container.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19354?
CVE-2019-19354 is considered to be a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2019-19354?
To remediate CVE-2019-19354, ensure you upgrade to a fixed version of Red Hat OpenShift Container Platform that addresses this vulnerability.
What software versions are affected by CVE-2019-19354?
CVE-2019-19354 affects Red Hat OpenShift Container Platform versions from 4.0 up to 4.4.3.
What is the impact of CVE-2019-19354?
The impact of CVE-2019-19354 allows an attacker with container access to modify the /etc/passwd file, leading to privilege escalation.
Is CVE-2019-19354 present in Red Hat Enterprise Linux 7.0 or 8.0?
No, CVE-2019-19354 is not applicable to Red Hat Enterprise Linux versions 7.0 or 8.0.