Incorrect Access Control in runc Affects Container Security
CVE-2019-19921
7HIGH
What is CVE-2019-19921?
The runc container runtime prior to version 1.0.0-rc10 is susceptible to an Incorrect Access Control flaw that can result in Privilege Escalation. Attackers can exploit this vulnerability by spawning two containers with custom volume-mount configurations and executing custom images. This poses a risk as it allows unauthorized access to resources and potential manipulation of the container environment. However, Docker is unaffected due to an implementation detail that mitigates the exploit.