CVE-2019-19348

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
02/04/2020
Last modified:
07/11/2023

Description

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:* 3.11.188-4 (excluding)
cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:* 4.0.0 (including) 4.1.37 (excluding)
cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:* 4.2.0 (including) 4.2.21 (excluding)
cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:* 4.3.0 (including) 4.3.5 (excluding)


References to Advisories, Solutions, and Tools