VDB
RHSA-2023%3A4025
RHSA-2023%3A4025
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in containerd, where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases. This issue can allow access to sensitive information or gain the ability to execute code in that container.
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64, openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64, * |
Timeline
- Jul 18, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:4025 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2174485 issue
- https://issues.redhat.com/browse/OCPBUGS-10417 advisory
- https://issues.redhat.com/browse/OCPBUGS-10784 advisory
- https://issues.redhat.com/browse/OCPBUGS-10933 advisory
- https://issues.redhat.com/browse/OCPBUGS-10935 advisory
- https://issues.redhat.com/browse/OCPBUGS-11667 advisory
- https://issues.redhat.com/browse/OCPBUGS-11785 advisory
- https://issues.redhat.com/browse/OCPBUGS-13790 advisory
- https://issues.redhat.com/browse/OCPBUGS-14260 advisory
- https://issues.redhat.com/browse/OCPBUGS-14445 advisory
- https://issues.redhat.com/browse/OCPBUGS-4862 advisory
- https://issues.redhat.com/browse/OCPBUGS-7336 advisory
- https://issues.redhat.com/browse/OCPBUGS-7843 advisory
- https://issues.redhat.com/browse/OCPBUGS-8037 advisory
- https://issues.redhat.com/browse/OCPBUGS-8056 advisory
- https://issues.redhat.com/browse/OCPBUGS-8085 advisory
- https://issues.redhat.com/browse/WINC-1037 advisory
- https://issues.redhat.com/browse/WINC-981 advisory
…and 10 more