Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc76-5925-c5p6

Опубликовано: 01 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.8
CVSS3: 5.4

Описание

Link Following in github.com/containers/common

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

Пакеты

Наименование

github.com/containers/common

go
Затронутые версииВерсия исправления

< 0.60.4

0.60.4

EPSS

Процентиль: 46%
0.00231
Низкий

5.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 5.4
ubuntu
9 месяцев назад

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

CVSS3: 5.4
redhat
9 месяцев назад

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

CVSS3: 5.4
nvd
9 месяцев назад

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

CVSS3: 5.4
debian
9 месяцев назад

A flaw was found in Go. When FIPS mode is enabled on a system, contain ...

CVSS3: 5.4
redos
8 месяцев назад

Уязвимость containers-common

EPSS

Процентиль: 46%
0.00231
Низкий

5.8 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-59