CVE-2020-1708: High severity redhat OpenShift Container Platform vulnerability
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mysql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Other sources
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-1708?
CVE-2020-1708 is an insecure modification vulnerability in the /etc/passwd file that affects openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to 4.3.
How does CVE-2020-1708 affect Red Hat OpenShift Container Platform?
CVE-2020-1708 affects Red Hat OpenShift Container Platform versions 3.11, 4.1, 4.2, and 4.3.
What is the severity of CVE-2020-1708?
The severity of CVE-2020-1708 is high with a CVSS score of 7.
How can an attacker exploit CVE-2020-1708?
An attacker with access to the running container can exploit CVE-2020-1708 by modifying the permissions of /etc/passwd to make them modifiable by users other than root.
How can I mitigate CVE-2020-1708 in Red Hat OpenShift Container Platform?
To mitigate CVE-2020-1708, ensure that the permissions of /etc/passwd are not modifiable by users other than root in the affected container.