In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
2020-02-10T01:15:10.483
2024-11-21T03:20:33.143
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxcontainers | lxc | 2.0.0 | Yes |