CVE Vulnerabilities

CVE-2021-20264

Incorrect Privilege Assignment

Published: Oct 06, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
OpenjdkOracle1.8.0 (including)1.8.0 (including)
OpenjdkOracle11 (including)11 (including)
Red Hat Build of OpenJDKRedHatopenjdk/openjdk-11-rhel7*
Red Hat Build of OpenJDKRedHatubi8/openjdk-11*
Red Hat Build of OpenJDKRedHatredhat-openjdk-18/openjdk18-openshift*
Red Hat Build of OpenJDKRedHatubi8/openjdk-8*

Potential Mitigations

References