A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HRed Hat OpenShift Container Platform
APPRedhat3.103.11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
Powiązane podatności
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam produkt
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam produkt
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam produkt
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework
CVE-2026-4408CRITICAL9.0PL ✓ten sam produkt
Samba: RCE przez command injection w 'check password script' z podstawieniem %u