A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cri-o | Kubernetes | - (including) | - (including) |
Red Hat OpenShift Container Platform 4.11 | RedHat | cri-o-0:1.24.4-10.rhaos4.11.git1ed5ac5.el8 | * |
Red Hat OpenShift Container Platform 4.12 | RedHat | cri-o-0:1.25.2-9.rhaos4.12.git0a083f9.el9 | * |