First published: Tue Jan 21 2020(Updated: )
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift | >=4.0<4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-1707 is high.
The affected software for CVE-2020-1707 is all openshift/postgresql-apb 4.x.x versions prior to 4.3.0.
CVE-2020-1707 allows an attacker with access to the container to modify the /etc/passwd file in the openshift/postgresql-apb container.
To fix CVE-2020-1707, it is recommended to update the openshift/postgresql-apb container to version 4.3.0 or later.
More information about CVE-2020-1707 can be found at the following references: [1] [2] [3]