This security bulletin contains one low risk vulnerability.
Exploit availability: NoDescription
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for "/etc/passwd" file after modification in the "openshift/ocp-release-operator-sdk". A local user with access to the system can modify the file and escalate privileges on the system.
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.Vulnerable software versions
Red Hat OpenShift Container Platform: 4.2.0 - 4.2.22, 4.1.0 - 4.1.27
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?