CVE-2019-19348: Red Hat Openshift
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Affected products
- Red Hat Openshift: before 3.11.188-4 (fixed in 3.11.188-4); from 4.0.0, before 4.1.37 (fixed in 4.1.37); from 4.2.0, before 4.2.21 (fixed in 4.2.21); from 4.3.0, before 4.3.5 (fixed in 4.3.5)
Published 2020-04-02. Last modified 2026-06-17.