CVE-2020-10695: High severity red hat single sign-on vulnerability
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.
Other sources
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/redhat-sso-7 container.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10695?
CVE-2020-10695 has a medium severity rating due to its potential for privilege escalation on affected systems.
How do I fix CVE-2020-10695?
To mitigate CVE-2020-10695, upgrade redhat-sso to version 7.4.4 or later.
What systems are affected by CVE-2020-10695?
CVE-2020-10695 affects redhat-sso versions prior to 7.4.4.
What type of vulnerability is CVE-2020-10695?
CVE-2020-10695 is an insecure modification flaw affecting the /etc/passwd file.
What can an attacker do with CVE-2020-10695?
An attacker with access to the container can modify the /etc/passwd file, potentially escalating their privileges.