Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w62-mvw6-xggx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.

EPSS

Процентиль: 16%
0.00053
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.1
nvd
больше 4 лет назад

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.

oracle-oval
больше 4 лет назад

ELSA-2021-9029: olcne security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-9028: olcne security update (IMPORTANT)

EPSS

Процентиль: 16%
0.00053
Низкий

Дефекты

CWE-732