Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37jw-xgjq-3fmq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

EPSS

Процентиль: 57%
0.00357
Низкий

8.8 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 7.5
redhat
больше 6 лет назад

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

CVSS3: 8.8
nvd
около 6 лет назад

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

EPSS

Процентиль: 57%
0.00357
Низкий

8.8 High

CVSS3

Дефекты

CWE-266
CWE-269