Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Aug 23, 2023
Withdrawn
This advisory was withdrawn on Aug 23, 2023
Package
Affected versions
< 2.3.0-30
Patched versions
None
Description
Published by the National Vulnerability Database
Jun 7, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 13, 2023
Withdrawn
Aug 23, 2023
Last updated
Aug 23, 2023
Withdrawn Advisory
This advisory has been withdrawn. This link is maintained to preserve external references.
Original Description
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.
References