HIGH🇬🇧 English

CVE-2019-14819

CVSS 8.8v3.1pub. 2020-01-07upd. 2024-11-21

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    3.103.11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam produkt

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam produkt

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam produkt

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework

CVE-2026-4408CRITICAL9.0PL ✓ten sam produkt

Samba: RCE przez command injection w 'check password script' z podstawieniem %u