Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10695

Опубликовано: 21 янв. 2020
Источник: redhat
CVSS3: 7

Описание

An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7redhat-sso-7-openshift-containersAffected
RHEL-8 based Middleware Containersrh-sso-7/sso74-openshift-rhel8FixedRHSA-2020:552915.12.2020
Text-Only RHSSOredhat-sso-7-openshift-containersFixedRHSA-2020:553315.12.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1817530containers/redhat-sso-7: /etc/passwd is given incorrect privileges

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.

CVSS3: 7.8
debian
больше 4 лет назад

An insecure modification flaw in the /etc/passwd file was found in the ...

github
больше 3 лет назад

An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.

7 High

CVSS3