VDB

RHSA-2023:4025

RHSA-2023:4025 PUBLISHED CVSS 7.300000190734863 HIGH

A flaw was found in containerd, where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases. This issue can allow access to sensitive information or gain the ability to execute code in that container.

Risk Scores

CVSS 3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Affected Products

VendorProductVersions
Red Hatopenshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.12openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64
Red Hatopenshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64 as a component of Red Hat OpenShift Container Platform 4.12*
Red Hatopenshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.12*, *, openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64
Red Hatopenshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64 as a component of Red Hat OpenShift Container Platform 4.12openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64, openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64, *

Timeline

  • Jul 18, 2023 CVE Published
  • May 1, 2026 Security Advisory
  • May 5, 2026 Distribution Patch
  • May 15, 2026 CVE Updated
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›