Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-27652

Опубликовано: 18 апр. 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 4.6
CVSS3: 5.3

Описание

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

upstream

needs-triage

Показывать по

4.6 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
почти 4 года назад

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

CVSS3: 5.3
nvd
почти 4 года назад

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

CVSS3: 5.3
debian
почти 4 года назад

A flaw was found in cri-o, where containers were incorrectly started w ...

CVSS3: 4.8
github
почти 4 года назад

Incorrect Default Permissions in CRI-O

4.6 Medium

CVSS2

5.3 Medium

CVSS3