{"api_version":"1","generated_at":"2026-07-23T12:20:05+00:00","cve":"CVE-2020-10728","urls":{"html":"https://cve.report/CVE-2020-10728","api":"https://cve.report/api/cve/CVE-2020-10728.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-10728","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-10728"},"summary":{"title":"CVE-2020-10728","description":"A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2022-08-16 21:15:00","updated_at":"2022-08-17 15:06:00"},"problem_types":["CWE-269"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1829674","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1829674","refsource":"MISC","tags":[],"title":"1829674 – (CVE-2020-10728) CVE-2020-10728 automationbroker/apb: permissive sudoers file","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-10728","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10728","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"10728","vulnerable":"1","versionEndIncluding":"2.0.4-1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"automationbroker","cpe5":"apb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2020-10728","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-266","cweId":"CWE-266"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"automationbroker/apb","version":{"version_data":[{"version_affected":"=","version_value":"up to and including 2.0.4-1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1829674","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1829674"}]}},"nvd":{"publishedDate":"2022-08-16 21:15:00","lastModifiedDate":"2022-08-17 15:06:00","problem_types":["CWE-269"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:automationbroker:apb:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.4-1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"10728","Ordinal":"171168","Title":"CVE-2020-10728","CVE":"CVE-2020-10728","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"10728","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}