A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
2022-04-18T17:15:16.977
2024-11-21T06:56:06.357
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | kubernetes | cri-o | - | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Application | mobyproject | moby | < 20.10.14 | Yes |
Application | redhat | openshift_container_platform | 3.11 | Yes |
Application | redhat | openshift_container_platform | 4.0 | Yes |