Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-4062

Опубликовано: 22 июн. 2020
Источник: nvd
CVSS3: 8.7
CVSS3: 9
CVSS2: 7.7
EPSS Низкий

Описание

In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the attacker's privileges to assume full control. A malicious actor who knows the IP address and port number of the Postgres database and has access into the Kubernetes cluster where Conjur runs can gain full read & write access to the Postgres database. This enables the attacker to write a policy that allows full access to retrieve any secret. This Helm chart is a method to install Conjur OSS into a Kubernetes environment. Hence, the systems impacted are only Conjur OSS systems that were deployed using this chart. Other deployments including Docker and the CyberArk Dynamic Access Provider (DAP) are not affected. To remediate this vulnerability, clone the latest Helm Chart and follow the upgrade instructions. If you

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cyberark:conjur_oss_helm_chart:*:*:*:*:*:*:*:*
Версия до 2.0.0 (исключая)

EPSS

Процентиль: 61%
0.00418
Низкий

8.7 High

CVSS3

9 Critical

CVSS3

7.7 High

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

EPSS

Процентиль: 61%
0.00418
Низкий

8.7 High

CVSS3

9 Critical

CVSS3

7.7 High

CVSS2

Дефекты

CWE-284
NVD-CWE-Other