It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mediawiki-apb
Original bug: https://bugzilla.redhat.com/showbug.cgi?id=1791534
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): openshift/mediawiki-apb: /etc/passwd is given incorrect privileges (CVE-2019-19345) openshift/mariadb-apb: /etc/passwd is given incorrect privileges (CVE-2019-19346) openshift/apb-base: /etc/passwd is given incorrect privileges (CVE-2019-19348) openshift/postgresql-apb: /etc/passwd is given incorrect privileges (CVE-2020-1707) openshift/mysql-apb: /etc/passwd is given incorrect privileges (CVE-2020-1708) openshift/mediawiki: /etc/passwd is given incorrect privileges (CVE-2020-1709) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): openshift/mediawiki-apb: /etc/passwd is given incorrect privileges (CVE-2019-19345) openshift/mariadb-apb: /etc/passwd is given incorrect privileges (CVE-2019-19346) openshift/apb-base: /etc/passwd is given incorrect privileges (CVE-2019-19348) openshift/postgresql-apb: /etc/passwd is given incorrect privileges (CVE-2020-1707) openshift/mysql-apb: /etc/passwd is given incorrect privileges (CVE-2020-1708) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.