Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg92-xfw5-qgvm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

EPSS

Процентиль: 41%
0.00189
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS3: 6.3
redhat
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS3: 5.3
nvd
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS3: 5.3
debian
больше 7 лет назад

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby f ...

suse-cvrf
больше 6 лет назад

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

EPSS

Процентиль: 41%
0.00189
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-250