High severity7.0NVD Advisory· Published Feb 7, 2020· Updated Jun 17, 2026
CVE-2020-1708
CVE-2020-1708
Description
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.3:*:*:*:*:*:*:*
- Range: 3.11, 4.1-4.3
- Range: openshift-enterprise version 3.11
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2020:0617nvd
- access.redhat.com/errata/RHSA-2020:0681nvd
- access.redhat.com/errata/RHSA-2020:0694nvd
News mentions
0No linked articles in our index yet.