cve/2020/CVE-2020-1706.md

18 lines
951 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-1706](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1706)
![](https://img.shields.io/static/v1?label=Product&message=openshift%2Fapb-tools-container&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20openshift-enterprise%20version%203.11%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-732&color=brighgreen)
### Description
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/apb-tools-container.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Live-Hack-CVE/CVE-2020-1706