Описание
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-642
https://bugzilla.redhat.com/show_bug.cgi?id=1219065docker: volume mounts allow LSM profile escalation
EPSS
Процентиль: 33%
0.00128
Низкий
4.3 Medium
CVSS2
Связанные уязвимости
ubuntu
около 10 лет назад
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
nvd
около 10 лет назад
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
debian
около 10 лет назад
Docker Engine before 1.6.1 allows local users to set arbitrary Linux S ...
EPSS
Процентиль: 33%
0.00128
Низкий
4.3 Medium
CVSS2