Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53c8-4j57-m6p5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

rkt through version 1.30.0 does not isolate processes in containers that are run with rkt enter. Processes run with rkt enter are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.

rkt through version 1.30.0 does not isolate processes in containers that are run with rkt enter. Processes run with rkt enter are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.

EPSS

Процентиль: 11%
0.00037
Низкий

7.7 High

CVSS3

Дефекты

CWE-250
CWE-269

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 6 лет назад

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.

CVSS3: 7.7
nvd
больше 6 лет назад

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.

CVSS3: 7.7
debian
больше 6 лет назад

rkt through version 1.30.0 does not isolate processes in containers th ...

EPSS

Процентиль: 11%
0.00037
Низкий

7.7 High

CVSS3

Дефекты

CWE-250
CWE-269