CVE-2020-1704
published 2020-02-17CVE-2020-1704: An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.4th percentile
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | openshift-service-mesh_kiali-rhel7-operator | — | — |
| redhat | openshift_service_mesh | < 1.0.8 | 1.0.8 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openshift-service-mesh/kiali-rhel7-operator: /etc/passwd is given incorrect privileges
vendor_redhat·2020-01-21·CVSS 7.0
CVE-2020-1704 [HIGH] CWE-732 openshift-service-mesh/kiali-rhel7-operator: /etc/passwd is given incorrect privileges
openshift-service-mesh/kiali-rhel7-operator: /etc/passwd is given incorrect privileges
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
An insecure modification vulnerability in the /etc/passwd file was found in the openshift-service-mesh/kiali-rhel7-operator. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Statement: By default this vulnerability is not exploitable in un-privilieged containers running on OpenShift Container Platform. This is because the system call SE
GHSA
GHSA-q483-wcf8-3hjc: An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1
ghsa_unreviewed·2022-05-24
CVE-2020-1704 [MEDIUM] CWE-732 GHSA-q483-wcf8-3hjc: An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2105 jenkins: REST APIs vulnerable to clickjacking
bugzilla·2020-01-31·CVSS 5.4
CVE-2020-2105 [MEDIUM] CVE-2020-2105 jenkins: REST APIs vulnerable to clickjacking
CVE-2020-2105 jenkins: REST APIs vulnerable to clickjacking
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
References:
https://jenkins.io/security/advisory/2020-01-29/#SECURITY-1704
http://www.openwall.com/lists/oss-security/2020/01/29/1
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1797069]
---
"Any security advisory related updates to Jenkins core or the plugins we include in the OpenShift Jenkins master image will only occur in the v3.11 and v4.x branches of this repository."
https://github.com/openshift/jenkins/blob/master/README.md#jenkins-security-advisories-the-master-image-from-this-repository-and-the-oc-binary
---
This bug has been fixed by https://errata.devel.redhat
Bugzilla
CVE-2020-1704 openshift-service-mesh/kiali-rhel7-operator: /etc/passwd is given incorrect privileges
bugzilla·2020-01-21·CVSS 7.0
CVE-2020-1704 [HIGH] CVE-2020-1704 openshift-service-mesh/kiali-rhel7-operator: /etc/passwd is given incorrect privileges
CVE-2020-1704 openshift-service-mesh/kiali-rhel7-operator: /etc/passwd is given incorrect privileges
It has been found that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/istio-kiali-rhel7-operator-container.
Original bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1791534
Discussion:
Statement:
By default this vulnerability is not exploitable in un-privilieged containers running on OpenShift Container Platform. This is because the system call SETUID and SETGID is blocked by the default seccomp policy.
---
Acknowledgments:
Name: Joseph LaMagna-Reiter (S
2020-02-17
Published