Количество 4
Количество 4
CVE-2026-58053
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
CVE-2026-58053
Gitea act_runner with the Docker backend (through act 0.262.0) passes ...
GHSA-8qf9-pc52-j7cm
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled.
BDU:2026-08914
Уязвимость компонента act_runner системы управления Git-репозиториями Gitea, позволяющая нарушителю повысить свои привилегии
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58053 Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled. | CVSS3: 9.9 | 0% Низкий | около 1 месяца назад | |
CVE-2026-58053 Gitea act_runner with the Docker backend (through act 0.262.0) passes ... | CVSS3: 9.9 | 0% Низкий | около 1 месяца назад | |
GHSA-8qf9-pc52-j7cm Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user who can run a workflow on a Docker-backed runner can create a job container with host namespaces and broad capabilities and escape to the host as root despite privileged mode being disabled. | CVSS3: 9.9 | 0% Низкий | около 1 месяца назад | |
BDU:2026-08914 Уязвимость компонента act_runner системы управления Git-репозиториями Gitea, позволяющая нарушителю повысить свои привилегии | CVSS3: 9.9 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу