Vulnerabilities > CVE-2019-19351 - Incorrect Privilege Assignment vulnerability in Redhat Openshift 3.11/4.0
Attack vector
LOCAL Attack complexity
HIGH Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/jenkins-slave-base-rhel7-containera as shipped in Openshift 4 and 3.11.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |