VYPR
Unrated severityNVD Advisory· Published Feb 23, 2021· Updated Aug 3, 2024

CVE-2021-20182

CVE-2021-20182

Description

A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the underlying node, such as the network and storage devices, to at least escalate their privileges to that of the cluster admin. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products

1
  • Range: github.com/openshift/builder v0.0.0-20210118193943-6d10f5202a76

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.