An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kubernetes-nmstate | Nmstate | * | 2.3.0 (excluding) |
RHEL-8-CNV-2.3 | RedHat | container-native-virtualization/kubevirt-cpu-model-nfd-plugin:v2.3.0-9 | * |
RHEL-8-CNV-2.3 | RedHat | container-native-virtualization/kubevirt-cpu-node-labeller:v2.3.0-9 | * |
RHEL-8-CNV-2.3 | RedHat | container-native-virtualization/kubevirt-kvm-info-nfd-plugin:v2.3.0-9 | * |