An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Kubernetes-nmstate | Nmstate | * | 2.3.0 (excluding) |
| RHEL-8-CNV-2.3 | RedHat | container-native-virtualization/kubevirt-cpu-model-nfd-plugin:v2.3.0-9 | * |
| RHEL-8-CNV-2.3 | RedHat | container-native-virtualization/kubevirt-cpu-node-labeller:v2.3.0-9 | * |
| RHEL-8-CNV-2.3 | RedHat | container-native-virtualization/kubevirt-kvm-info-nfd-plugin:v2.3.0-9 | * |