CVE-2020-1706: High severity redhat OpenShift Container Platform vulnerability
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/apb-tools-container.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1706?
CVE-2020-1706 is considered a high severity vulnerability due to the potential for unauthorized modifications of critical system files.
How do I fix CVE-2020-1706?
To fix CVE-2020-1706, update Red Hat OpenShift Container Platform to the latest patched version beyond 4.3.
What versions are affected by CVE-2020-1706?
CVE-2020-1706 affects Red Hat OpenShift Container Platform versions 3.11 and 4.1 to 4.3.
What is the impact of exploiting CVE-2020-1706?
Exploiting CVE-2020-1706 allows an attacker with access to a running container to modify the /etc/passwd file, potentially enabling privilege escalation.
Is there a workaround for CVE-2020-1706 if I cannot update?
A possible workaround for CVE-2020-1706 includes implementing strict access controls to the running containers to prevent unauthorized access.