Privilege Escalation Vulnerability in OpenShift Container Platform by Red Hat
CVE-2019-14819
7.5HIGH
Key Information:
- Vendor
- [red Hat]
- Status
- Openshift-ansible
- Vendor
- CVE Published:
- 7 January 2020
Summary
A privilege escalation vulnerability exists in the OpenShift Container Platform 3.x during the upgrade process. When using CRI-O, the dockergc service account is incorrectly assigned to the current namespace of the user performing the upgrade. This misconfiguration can permit an unprivileged user to escalate their privileges, gaining access to greater permissions than intended under the privileged Security Context Constraints. This flaw can potentially lead to unauthorized access and manipulation of resources within the container environment.
Affected Version(s)
openshift-ansible 3.x
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved