VDB
RHSA-2021:0945
RHSA-2021:0945
PUBLISHED
CVSS 7 HIGH
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Risk Scores
CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Build of OpenJDK |
Timeline
- Mar 19, 2021 CVE Published
- Mar 18, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:0945 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/articles/4859371 advisory
- https://catalog.redhat.com/software/containers/openjdk/openjdk-11-rhel7/5bf57185dd19c775cddc4ce5?tag=1.1-12&push_date=1616089599000 advisory
- https://catalog.redhat.com/software/containers/ubi8/openjdk-11/5dd6a4b45a13461646f677f4?container-tabs=overview&tag=1.3-10&push_date=1616090044000 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1932283 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0945.json advisory
- https://access.redhat.com/security/cve/CVE-2021-20264 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-20264 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-20264 advisory