Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20208

Опубликовано: 12 апр. 2021
Источник: redhat
CVSS3: 6.1

Описание

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

A flaw was found in cifs-utils. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

Отчет

This flaw is rated as having Moderate impact because of the need to have elevated privileges and limited possibilities of the attack: an attacker will not get actual credentials cache accessed by themselves, but might cause an authentication attempt to an SMB server and may be succeed in file access.

Меры по смягчению последствий

DFS and multiuser mounts can be disabled in the container SMB mounts options i.e. adding 'nodfs' and removing 'multiuser' (if present).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6cifs-utilsOut of support scope
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux 7cifs-utilsWill not fix
Red Hat Enterprise Linux 7sambaNot affected
Red Hat Enterprise Linux 8cifs-utilsAffected
Red Hat Enterprise Linux 8sambaNot affected
Red Hat Enterprise Linux 9cifs-utilsNot affected
Red Hat Enterprise Linux 9sambaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1921116cifs-utils: Container can use kerberos cache from the host via mount.cifs/cifs.upcall

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 5 лет назад

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 6.1
nvd
почти 5 лет назад

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 6.1
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 6.1
debian
почти 5 лет назад

A flaw was found in cifs-utils in versions before 6.13. A user when mo ...

suse-cvrf
почти 5 лет назад

Security update for cifs-utils

6.1 Medium

CVSS3