Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-27561

Опубликовано: 03 мар. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7

Описание

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

РелизСтатусПримечание
bionic

released

1.1.4-0ubuntu1~18.04.2
devel

released

1.1.4-0ubuntu4
esm-apps/bionic

released

1.1.4-0ubuntu1~18.04.2
esm-apps/xenial

released

1.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm4
esm-infra/focal

not-affected

1.1.4-0ubuntu1~20.04.3
focal

released

1.1.4-0ubuntu1~20.04.3
jammy

released

1.1.4-0ubuntu1~22.04.3
kinetic

released

1.1.4-0ubuntu1~22.10.3
lunar

released

1.1.4-0ubuntu3.1
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 30%
0.00107
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
nvd
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7
debian
больше 2 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation ...

CVSS3: 7
github
больше 2 лет назад

Opencontainers runc Incorrect Authorization vulnerability

EPSS

Процентиль: 30%
0.00107
Низкий

7 High

CVSS3

Уязвимость CVE-2023-27561