CVE-2020-1742: Nmstate Kubernetes-Nmstate

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.

Affected products

  • Nmstate Kubernetes-Nmstate: before 2.3.0 (fixed in 2.3.0)
  • Red Hat Openshift Virtualization: version 2 only

Published 2021-06-07. Last modified 2026-06-17.