Логотип exploitDog
bind:"CVE-2021-20291" OR bind:"CVE-2021-3602"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-20291" OR bind:"CVE-2021-3602"

Количество 23

Количество 23

rocky логотип

RLSA-2021:4154

больше 3 лет назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4154

больше 3 лет назад

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3312-1

почти 3 года назад

Security update for libcontainers-common

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:23018-1

больше 3 лет назад

Security update for conmon, libcontainers-common, libseccomp, podman

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:23018-1

больше 3 лет назад

Security update for conmon, libcontainers-common, libseccomp, podman

EPSS: Низкий
ubuntu логотип

CVE-2021-20291

около 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-20291

около 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-20291

около 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-20291

около 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-3602

больше 3 лет назад

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-3602

почти 4 года назад

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2021-3602

больше 3 лет назад

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3602

около 1 года назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-3602

больше 3 лет назад

An information disclosure flaw was found in Buildah, when building con ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-7qw8-847f-pggm

около 4 лет назад

Improper Locking in github.com/containers/storage

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2021:4222

больше 3 лет назад

Moderate: container-tools:3.0 security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2021:4221

больше 3 лет назад

Moderate: container-tools:2.0 security update

EPSS: Низкий
github логотип

GHSA-7638-r9r3-rmjj

почти 4 года назад

Buildah processes using chroot isolation may leak environment values to intermediate processes

CVSS3: 5.5
EPSS: Низкий
oracle-oval логотип

ELSA-2021-4222

больше 3 лет назад

ELSA-2021-4222: container-tools:3.0 security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4221

больше 3 лет назад

ELSA-2021-4221: container-tools:2.0 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2021:4154

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

больше 3 лет назад
oracle-oval логотип
ELSA-2021-4154

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3312-1

Security update for libcontainers-common

почти 3 года назад
suse-cvrf логотип
openSUSE-SU-2022:23018-1

Security update for conmon, libcontainers-common, libseccomp, podman

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:23018-1

Security update for conmon, libcontainers-common, libseccomp, podman

больше 3 лет назад
ubuntu логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVSS3: 5.6
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building con ...

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7qw8-847f-pggm

Improper Locking in github.com/containers/storage

CVSS3: 6.5
0%
Низкий
около 4 лет назад
rocky логотип
RLSA-2021:4222

Moderate: container-tools:3.0 security and bug fix update

0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2021:4221

Moderate: container-tools:2.0 security update

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7638-r9r3-rmjj

Buildah processes using chroot isolation may leak environment values to intermediate processes

CVSS3: 5.5
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2021-4222

ELSA-2021-4222: container-tools:3.0 security and bug fix update (MODERATE)

больше 3 лет назад
oracle-oval логотип
ELSA-2021-4221

ELSA-2021-4221: container-tools:2.0 security update (MODERATE)

больше 3 лет назад

Уязвимостей на страницу