Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22036

Опубликовано: 16 апр. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access to the Rancher container itself. In production environments, further privilege escalation is possible based on living off the land within the Rancher container itself. For the test and development environments, based on a –privileged Docker container, it is possible to escape the Docker container and gain execution access on the host system.

This issue affects rancher: from 2.7.0 before 2.7.16, from 2.8.0 before 2.8.9, from 2.9.0 before 2.9.3.

EPSS

Процентиль: 32%
0.00124
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.1
github
больше 1 года назад

Rancher Remote Code Execution via Cluster/Node Drivers

suse-cvrf
больше 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 32%
0.00124
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-269