Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj3f-3286-r4pf

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Path Traversal in Docker

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

Пакеты

Наименование

github.com/docker/docker

go
Затронутые версииВерсия исправления

< 1.3.3

1.3.3

EPSS

Процентиль: 78%
0.01209
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 5 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

redhat
больше 10 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
nvd
больше 5 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 8.6
debian
больше 5 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote atta ...

EPSS

Процентиль: 78%
0.01209
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22