CVE-2020-1707: High severity redhat Openshift vulnerability
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Other sources
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/postgresql-apb.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1707?
The severity of CVE-2020-1707 is high.
What is the affected software for CVE-2020-1707?
The affected software for CVE-2020-1707 is all openshift/postgresql-apb 4.x.x versions prior to 4.3.0.
How does CVE-2020-1707 impact the system?
CVE-2020-1707 allows an attacker with access to the container to modify the /etc/passwd file in the openshift/postgresql-apb container.
How can CVE-2020-1707 be fixed?
To fix CVE-2020-1707, it is recommended to update the openshift/postgresql-apb container to version 4.3.0 or later.
Where can I find more information about CVE-2020-1707?
More information about CVE-2020-1707 can be found at the following references: [1] [2] [3]