An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift 4.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift | Redhat | 4.0 (including) | 4.0 (including) |
Red Hat OpenShift Container Platform 4.1 | RedHat | openshift4/ose-ansible-operator:v4.1.41-202004151639 | * |
Red Hat OpenShift Container Platform 4.2 | RedHat | openshift4/ose-ansible-operator:v4.2.27-202003301126 | * |
Red Hat OpenShift Container Platform 4.3 | RedHat | openshift4/ose-ansible-operator:v4.3.5-202003020549 | * |