Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj3f-3286-r4pf

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Path Traversal in Docker

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

Пакеты

Наименование

github.com/docker/docker

go
Затронутые версииВерсия исправления

< 1.3.3

1.3.3

EPSS

Процентиль: 92%
0.04923
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 7 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

redhat
почти 12 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
nvd
почти 7 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
msrc
около 5 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
debian
почти 7 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote atta ...

EPSS

Процентиль: 92%
0.04923
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22