CVE-2020-8903 is a privilege escalation vulnerability in Google Cloud Platform's guest-oslogin (versions 20190304-20200507), also affecting OpenSUSE guest-oslogin and Leap. A user with only "roles/compute.osLogin" can escalate to root by manipulating DHCP settings to impersonate the GCE metadata server. This high-severity vulnerability (CVSS 7.8) has a local attack vector with low complexity, leading to full confidentiality, integrity, and availability compromise. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20190304.00, <= 20200507.00CPE matchmatch criteria | cpe:2.3:a:google:guest-oslogin:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* | ||
>= 20190304, < 20200507CPE match | cpe:2.3:a:google:guest-oslogin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Compute Engine OS Login Privilege Escalation Vulnerabilities
Jun 19, 2020Compute Engine OS Login Privilege Escalation
Jun 19, 2020VMs that have OS Login enabled might be susceptible to privilege escalation vulnerabilities. These vulnerabilities gives users that are granted OS Login permissions (but not given admin access) the ability to escalate to root access in the VM.