Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-28914

Опубликовано: 17 нояб. 2020
Источник: nvd
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:katacontainers:kata-containers:*:*:*:*:*:*:*:*
Версия до 1.11.5 (исключая)

EPSS

Процентиль: 16%
0.00053
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-732

Связанные уязвимости

github
около 3 лет назад

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.

oracle-oval
больше 4 лет назад

ELSA-2021-9029: olcne security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-9028: olcne security update (IMPORTANT)

EPSS

Процентиль: 16%
0.00053
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-732