CVE-2021-20264

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/10/2021
Last modified:
21/10/2022

Description

An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oracle:openjdk:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:11:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools