Privilege Escalation Vulnerability in OpenShift Container Platform by Red Hat
CVE-2019-14819

7.5HIGH

Key Information:

Vendor
[red Hat]
Status
Openshift-ansible
Vendor
CVE Published:
7 January 2020

Summary

A privilege escalation vulnerability exists in the OpenShift Container Platform 3.x during the upgrade process. When using CRI-O, the dockergc service account is incorrectly assigned to the current namespace of the user performing the upgrade. This misconfiguration can permit an unprivileged user to escalate their privileges, gaining access to greater permissions than intended under the privileged Security Context Constraints. This flaw can potentially lead to unauthorized access and manipulation of resources within the container environment.

Affected Version(s)

openshift-ansible 3.x

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.