CVE Vulnerabilities

CVE-2021-20264

Incorrect Privilege Assignment

Published: Oct 06, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu

An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Openjdk Oracle 1.8.0 (including) 1.8.0 (including)
Openjdk Oracle 11 (including) 11 (including)
Red Hat Build of OpenJDK RedHat openjdk/openjdk-11-rhel7 *
Red Hat Build of OpenJDK RedHat ubi8/openjdk-11 *
Red Hat Build of OpenJDK RedHat redhat-openjdk-18/openjdk18-openshift *
Red Hat Build of OpenJDK RedHat ubi8/openjdk-8 *

Potential Mitigations

References