Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27561

Опубликовано: 03 мар. 2023
Источник: nvd
CVSS3: 7
EPSS Низкий

Описание

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
Версия до 1.1.5 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 30%
0.00107
Низкий

7 High

CVSS3

Дефекты

CWE-706
CWE-706

Связанные уязвимости

CVSS3: 7
ubuntu
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
redhat
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7
debian
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation ...

CVSS3: 7
github
больше 2 лет назад

Opencontainers runc Incorrect Authorization vulnerability

EPSS

Процентиль: 30%
0.00107
Низкий

7 High

CVSS3

Дефекты

CWE-706
CWE-706