VDB
CVE-2020-1742
CVE-2020-1742
PUBLISHED
CVSS 4.400000095367432 MEDIUM
Reported by redhat · Published June 7, 2021
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.
Risk Scores
CVSS 2.0
4.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | nmstate/kubernetes-nmstate-handler | kubernetes-nmstate-handler-container-v2.3.0-30 |
| github.com | nmstate/kubernetes-nmstate | 0, 0 |
| n/a | nmstate/kubernetes-nmstate-handler | kubernetes-nmstate-handler-container-v2.3.0-30, * |
Timeline
- Jun 7, 2021 CVE Published
- Jun 8, 2021 EPSS Score
- Aug 9, 2021 EPSS Score
- Oct 9, 2021 EPSS Score
- Nov 23, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 9, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 11, 2022 EPSS Score
- Jun 11, 2022 EPSS Score
- Aug 12, 2022 EPSS Score
- Oct 12, 2022 EPSS Score
References
- x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2020-1742 advisory
- https://github.com/advisories/GHSA-jw82-xjgr-g6f8 advisory