CVE-2020-1690: Medium severity red hat rpm plugin for selinux vulnerability
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could start or stop services, possibly causing a denial of service. Versions before openstack-selinux 0.8.24 are affected.
Other sources
As of 15, openstack-selinux prevents a non-root user in a container from privilege escalation. In 13 and before, openstack-selinux didn't have this functionality (that is, selinux separation wasn't possible). Updates to the policy in [1] broke 15's functionality. A non-root user in one or more RHOSP containers can send messages to the dbus. With access to the dbus, services could be started or stopped, therefore a DoS is possible.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security flaw?
The vulnerability ID of this security flaw is CVE-2020-1690.
What is the severity level of CVE-2020-1690?
CVE-2020-1690 has a severity level of medium.
What is the affected software by CVE-2020-1690?
The affected software by CVE-2020-1690 includes openstack-selinux version 0.8.24, Redhat Openstack-selinux version up to exclusive 0.8.24, Redhat Openstack Platform version 15.0, and Redhat Openstack Platform version 16.1.
How can the vulnerability be fixed?
To fix CVE-2020-1690, it is recommended to apply the remedy version 0.8.24 for openstack-selinux or upgrade to a higher version of Redhat Openstack Platform.
Is there any reference for more information about CVE-2020-1690?
Yes, you can find more information about CVE-2020-1690 at the following references: [Bugzilla Bug 1789640](https://bugzilla.redhat.com/show_bug.cgi?id=1789640) and [Bugzilla Bug 1738134](https://bugzilla.redhat.com/show_bug.cgi?id=1738134).