Описание
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.24.1 (включая)
cpe:2.3:a:portainer:portainer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01917
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-732
Связанные уязвимости
github
больше 3 лет назад
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.
EPSS
Процентиль: 83%
0.01917
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-732