Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpvm-3wq2-2wvm

Опубликовано: 03 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

Opencontainers runc Incorrect Authorization vulnerability

runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Ссылки

Пакеты

Наименование

github.com/opencontainers/runc

go
Затронутые версииВерсия исправления

>= 1.0.0-rc95, < 1.1.5

1.1.5

EPSS

Процентиль: 30%
0.00107
Низкий

7 High

CVSS3

Дефекты

CWE-706

Связанные уязвимости

CVSS3: 7
ubuntu
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
redhat
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
nvd
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7
debian
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation ...

EPSS

Процентиль: 30%
0.00107
Низкий

7 High

CVSS3

Дефекты

CWE-706