Security Advisory

CVE-2019-19355

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-03-18 16:35:00
Last updated 2024-08-05 02:16:47
Assigner redhat
CVSS score 7.0
State PUBLISHED

Description

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift 4.