REDHAT-BUG-1793297: Medium severity Openshift mediawiki-container vulnerability
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mediawiki-container.
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1793297?
The severity of REDHAT-BUG-1793297 is considered critical due to the potential for privilege escalation.
How do I fix REDHAT-BUG-1793297?
To fix REDHAT-BUG-1793297, update the mediawiki-container to the latest patched version provided by OpenShift.
Who is affected by REDHAT-BUG-1793297?
Users running the OpenShift mediawiki-container are affected by REDHAT-BUG-1793297.
What can an attacker do with REDHAT-BUG-1793297?
An attacker can exploit REDHAT-BUG-1793297 to modify /etc/passwd and gain unauthorized privileges within the container.
Is REDHAT-BUG-1793297 a container vulnerability?
Yes, REDHAT-BUG-1793297 is a vulnerability specific to the OpenShift mediawiki-container.