Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw82-xjgr-g6f8

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management

Withdrawn Advisory

This advisory has been withdrawn. This link is maintained to preserve external references.

Original Description

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.

Пакеты

Наименование

github.com/nmstate/kubernetes-nmstate

go
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 12%
0.0004
Низкий

7 High

CVSS3

Дефекты

CWE-269
CWE-732

Связанные уязвимости

CVSS3: 7
redhat
около 6 лет назад

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.

CVSS3: 7
nvd
больше 4 лет назад

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.

EPSS

Процентиль: 12%
0.0004
Низкий

7 High

CVSS3

Дефекты

CWE-269
CWE-732