{"id":"CVE-2021-20264","details":"An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with access to the container to modify the /etc/passwd and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.","modified":"2026-07-08T06:47:57.472560919Z","published":"2021-10-06T16:15:07.297Z","database_specific":{"unresolved_ranges":[{"vendor_product":"oracle:openjdk","cpes":["cpe:2.3:a:oracle:openjdk:1.8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.8.0"},{"last_affected":"1.8.0"},{"introduced":"1.8.0"},{"last_affected":"1.8.0"},{"introduced":"1.8.0"},{"last_affected":"1.8.0"}],"source":"CPE_STRING"}]},"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1932283"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openjdk/jdk","events":[{"introduced":"da75f3c4ad5bdf25167a3ed80e51f567ab3dbd01"},{"last_affected":"da75f3c4ad5bdf25167a3ed80e51f567ab3dbd01"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:oracle:openjdk:11:*:*:*:*:*:*:*","extracted_events":[{"introduced":"11"},{"last_affected":"11"}]}}],"versions":["11","jdk-11-ga","jdk-11+28"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20264.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/openjdk/jdk15u","events":[{"introduced":"a9a271179d2a7952154b7509a999b100cc98b13c"},{"last_affected":"a9a271179d2a7952154b7509a999b100cc98b13c"}],"database_specific":{"cpe":"cpe:2.3:a:oracle:openjdk:11:*:*:*:*:*:*:*","extracted_events":[{"introduced":"11"},{"last_affected":"11"}],"source":"CPE_STRING"}}],"versions":["11","jdk-11+0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20264.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}