openshift: Users with permission to schedule pods on master nodes can access credentials for AWS IAM roles
Published Mar 19, 2021
7.2
HIGHCVSS 3.1
EPSS 1.25%
Description
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing management access to AWS resources. With access to the security credentials, the user then has access to the entire infrastructure. Impact to data and system availability is high.
Affected products
- Vendor n/a Product OpenShift Container Platform Defaultn/a
- Version OpenShift Container Platform 4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | OpenShift Container Platform | n/a |
|
- 4.0
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-kube-apiserver-operator
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-kube-apiserver-operator | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Do not run untrusted workloads with `hostnetwork` access on master nodes. If additional workloads are run on master hosts, use caution when providing access to hostnetwork. A workload that runs hostnetwork on a master host is effectively root on the cluster and must be trusted accordingly. https://docs.openshift.com/container-platform/4.4/authentication/managing-security-context-constraints.html
References (6)
- https://access.redhat.com/security/cve/CVE-2019-10200 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1730161 x_refsource_MISCIssue TrackingMitigationPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2220 Advisory
- https://github.com/openshift/cluster-kube-apiserver-operator/pull/524 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10200
- https://www.cve.org/CVERecord?id=CVE-2019-10200
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-10200 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1730161 | x_refsource_MISCIssue TrackingMitigationPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2220 | Advisory | |
| https://github.com/openshift/cluster-kube-apiserver-operator/pull/524 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10200 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-10200 |
Change history (0)
No recorded changes yet.