Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwqp-p498-93jr

Опубликовано: 24 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with access to execute commands in a running Pod to elevate their user privileges.

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with access to execute commands in a running Pod to elevate their user privileges.

EPSS

Процентиль: 27%
0.00097
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.8
nvd
больше 1 года назад

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with privileged access to execute commands in a running Pod to elevate their user privileges.

EPSS

Процентиль: 27%
0.00097
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-732