CVE-2019-19355: Red Hat Openshift
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift 4.
Affected products
- Red Hat Openshift: version 4.0 only
Published 2020-03-18. Last modified 2026-06-17.