Privilege Escalation Vulnerability in OpenShift Container Platform by Red Hat
CVE-2019-14819
7.5HIGH
What is CVE-2019-14819?
A privilege escalation vulnerability exists in the OpenShift Container Platform 3.x during the upgrade process. When using CRI-O, the dockergc service account is incorrectly assigned to the current namespace of the user performing the upgrade. This misconfiguration can permit an unprivileged user to escalate their privileges, gaining access to greater permissions than intended under the privileged Security Context Constraints. This flaw can potentially lead to unauthorized access and manipulation of resources within the container environment.
Affected Version(s)
openshift-ansible 3.x