#VU25999 Incorrect default permissions in Red Hat OpenShift Container Platform - CVE-2019-19355
Published: March 11, 2020 / Updated: January 25, 2023
Red Hat OpenShift Container Platform
Red Hat Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for "/etc/passwd" file after modification in the "openshift/ocp-release-operator-sdk". A local user with access to the system can modify the file and escalate privileges on the system.