Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3j5-32m5-58c2

Опубликовано: 20 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Privilege Elevation in runc

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

Пакеты

Наименование

github.com/opencontainers/runc

go
Затронутые версииВерсия исправления

< 0.1.0

0.1.0

EPSS

Процентиль: 28%
0.00098
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

redhat
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

CVSS3: 7.8
nvd
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

CVSS3: 7.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.8
debian
около 9 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker befo ...

EPSS

Процентиль: 28%
0.00098
Низкий

7.8 High

CVSS3

Дефекты

CWE-269