Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mq47-6wwv-v79w

Опубликовано: 04 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Path traversal in claircore

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

Пакеты

Наименование

github.com/quay/claircore

go
Затронутые версииВерсия исправления

< 0.4.8

0.4.8

Наименование

github.com/quay/claircore

go
Затронутые версииВерсия исправления

>= 1.0.0, < 1.1.0

1.1.0

Наименование

github.com/quay/claircore

go
Затронутые версииВерсия исправления

>= 0.5.0, < 0.5.5

0.5.5

EPSS

Процентиль: 92%
0.08656
Низкий

7.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
redhat
больше 4 лет назад

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

CVSS3: 9.8
nvd
почти 4 года назад

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

EPSS

Процентиль: 92%
0.08656
Низкий

7.8 High

CVSS3

Дефекты

CWE-22