Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4pj-mx9f-m2mh

Опубликовано: 26 сент. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.1

Описание

Duplicate Advisory: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-f748-7hpg-88ch. This link is maintained to preserve external references.

Original Description

NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.

Пакеты

Наименование

github.com/NVIDIA/nvidia-container-toolkit

go
Затронутые версииВерсия исправления

< 1.16.2

1.16.2

4.1 Medium

CVSS3

Дефекты

CWE-367

4.1 Medium

CVSS3

Дефекты

CWE-367