openshift/apb-tools: /etc/passwd is given incorrect privileges
Published Mar 9, 2020
7.0
HIGHCVSS 3.1
EPSS 0.24%
Description
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/apb-tools-container.
Affected products
-
- Version from openshift-enterprise version 4.1 to, including 4.3StatusaffectedConstraints-
- Version openshift-enterprise version 3.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Openshift/apb-Tools-Container | n/a |
|
- 3.11
- 4.1
- 4.2
- 4.3
No data.
Red Hat OpenShift Container Platform 4.2
openshift4/apb-tools:v4.2.34-202005252115
Fixed · RHSA-2020:2305
Red Hat OpenShift Container Platform 4.3
openshift4/apb-tools:v4.3.24-202006011815
Fixed · RHSA-2020:2442
Red Hat OpenShift Container Platform 3.11
openshift3/apb-tools
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.2 | openshift4/apb-tools:v4.2.34-202005252115 | Fixed | RHSA-2020:2305 |
| Red Hat OpenShift Container Platform 4.3 | openshift4/apb-tools:v4.3.24-202006011815 | Fixed | RHSA-2020:2442 |
| Red Hat OpenShift Container Platform 3.11 | openshift3/apb-tools | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
By default this vulnerability is not exploitable in un-privilieged containers running on OpenShift Container Platform. This is because the system call SETUID and SETGID is blocked by the default seccomp policy.
References (5)
- https://access.redhat.com/security/cve/CVE-2020-1706 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1793302 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1706 Issue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1706
- https://www.cve.org/CVERecord?id=CVE-2020-1706
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-1706 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1793302 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1706 | Issue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-1706 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-1706 |
Change history (0)
No recorded changes yet.