Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37841

Опубликовано: 12 авг. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:docker:desktop:*:*:*:*:windows:*:*:*
Версия до 3.6.0 (исключая)

EPSS

Процентиль: 39%
0.00172
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

EPSS

Процентиль: 39%
0.00172
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732