Load malicious images may cause process to be hijacked
CVE-2021-33636

7.8HIGH

Key Information:

Vendor

Openeuler

Status
Vendor
CVE Published:
29 October 2023

What is CVE-2021-33636?

The iSulad container management system, utilized in OpenEuler, contains a vulnerability that allows attackers to use the 'isula load' command to load malicious container images. This flaw enables an attacker to execute arbitrary code, potentially compromising the security of the host environment. Attackers leveraging this vulnerability can gain unauthorized access, leading to possible data breaches or system integrity violations.

Affected Version(s)

iSulad Linux 0 <= 2.0.8-20210518.144540.git5288ed93,2.0.18-10,2.1.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.