Логотип exploitDog
bind:CVE-2023-38496
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38496

Количество 3

Количество 3

nvd логотип

CVE-2023-38496

больше 2 лет назад

Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mmx5-32m4-wxvx

больше 2 лет назад

Ineffective privileges drop when requesting container network

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0244-1

больше 1 года назад

Security update for apptainer

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-38496

Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-mmx5-32m4-wxvx

Ineffective privileges drop when requesting container network

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
openSUSE-SU-2024:0244-1

Security update for apptainer

больше 1 года назад

Уязвимостей на страницу