There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond
History

Wed, 16 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud migrate To Containers
CPEs cpe:2.3:a:google_cloud:migrate_to_containers:*:*:*:*:*:*:*:*
Vendors & Products Google Cloud
Google Cloud migrate To Containers
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 09:00:00 +0000

Type Values Removed Values Added
Description There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This posed a security risk if the "analyze" or "generate" commands were interrupted or skipping the action to delete the local user “m2cuser”. We recommend upgrading to 1.2.3 or beyond
Title Insecure user permissions in Google Cloud Migrate to Containers for Windows
Weaknesses CWE-276
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P/AU:Y/R:A/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2024-10-16T08:43:51.015Z

Updated: 2024-10-16T16:24:16.999Z

Reserved: 2024-10-11T11:17:41.006Z

Link: CVE-2024-9858

cve-icon Vulnrichment

Updated: 2024-10-16T16:24:04.455Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-16T09:15:03.550

Modified: 2024-10-16T17:35:08.130

Link: CVE-2024-9858

cve-icon Redhat

No data.