CVE-2021-20182
Summary
| CVE | CVE-2021-20182 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-23 22:15:00 UTC |
| Updated | 2021-05-21 15:28:00 UTC |
| Description | A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the underlying node, such as the network and storage devices, to at least escalate their privileges to that of the cluster admin. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Openshift Container Platform | All | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.4 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.5 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.6 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.4 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.5 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1915110 – (CVE-2021-20182) CVE-2021-20182 openshift: builder allows read and write of block devices | MISC | bugzilla.redhat.com | Issue Tracking, Mitigation, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.