CVE-2020-1708 is a privilege escalation vulnerability affecting Red Hat OpenShift Container Platform versions 3.11 and 4.1-4.3, specifically within the openshift/mysql-apb container. Multiple containers incorrectly set permissions on /etc/passwd, allowing non-root users to modify it. An attacker with container access could exploit this to add a new user and gain elevated privileges. This vulnerability has a CVSS score of 7.0 (High), indicating a significant risk due to its potential for complete compromise of confidentiality, integrity, and availability. The attack complexity is high, requiring local access to the container. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.