Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfjr-r7c6-mq2h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.

EPSS

Процентиль: 29%
0.00108
Низкий

7 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 7
redhat
около 6 лет назад

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.

CVSS3: 7
nvd
около 6 лет назад

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.

EPSS

Процентиль: 29%
0.00108
Низкий

7 High

CVSS3

Дефекты

CWE-266
CWE-269