{"id":"GHSA-jw82-xjgr-g6f8","summary":"Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management","details":"## Withdrawn Advisory\nThis advisory has been withdrawn. This link is maintained to preserve external references.\n\n## Original Description\nAn insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes-nmstate-handler-container-v2.3.0-30 are affected.","aliases":["CVE-2020-1742"],"modified":"2026-09-10T03:49:39.259913839Z","published":"2022-05-24T19:04:13Z","withdrawn":"2023-08-23T21:44:47Z","database_specific":{"github_reviewed_at":"2023-07-13T23:17:51Z","nvd_published_at":"2021-06-07T20:15:00Z","cwe_ids":["CWE-269","CWE-732"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1742"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1803608"}],"affected":[{"package":{"name":"github.com/nmstate/kubernetes-nmstate","ecosystem":"Go","purl":"pkg:golang/github.com/nmstate/kubernetes-nmstate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jw82-xjgr-g6f8/GHSA-jw82-xjgr-g6f8.json","last_known_affected_version_range":"\u003c 2.3.0-30"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}