An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift_container_platform | Redhat | 4.4 (including) | 4.4.3 (excluding) |
Red Hat OpenShift Container Platform 4.4 | RedHat | openshift4/ose-metering-hadoop:v4.4.0-202004261927 | * |