Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm9x-c3rh-7rc4

Опубликовано: 29 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation

Impact

It is possible to craft an environment variable with newlines to add entries to a container's /etc/passwd. It is possible to circumvent admission validation of username/UID by adding such an entry.

Note: because the pod author is in control of the container's /etc/passwd, this is not considered a new risk factor. However, this advisory is being opened for transparency and as a way of tracking fixes.

Patches

1.26.0 will have the fix. More patches will be posted as they're available.

Workarounds

Additional security controls like SELinux should prevent any damage a container is able to do with root on the host. Using SELinux is recommended because this class of attack is already possible by manually editing the container's /etc/passwd

References

Пакеты

Наименование

github.com/cri-o/cri-o

go
Затронутые версииВерсия исправления

< 1.26.0

1.26.0

EPSS

Процентиль: 12%
0.00042
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-538
CWE-913

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVSS3: 7.8
redhat
больше 2 лет назад

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVSS3: 7.8
nvd
больше 1 года назад

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVSS3: 7.8
debian
больше 1 года назад

A vulnerability was found in cri-o. This issue allows the addition of ...

CVSS3: 7.8
redos
около 1 года назад

Уязвимость cri-o

EPSS

Процентиль: 12%
0.00042
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-538
CWE-913