Run copy with container in a malicious directory may cause container escaping
CVE-2021-33638

8.4HIGH

Key Information:

Vendor

Openeuler

Status
Vendor
CVE Published:
29 October 2023

What is CVE-2021-33638?

An attacker leveraging the isula cp command can exploit a vulnerability to copy files from a compromised container to the host machine. This poses a significant risk as it allows the attacker to escape the container and potentially gain unauthorized access to the host system. Users of iSulad should ensure that they update to the latest version and follow security best practices to mitigate this risk.

Affected Version(s)

iSulad Linux 0 <= 2.0.8-20210518.144540.git5288ed93,2.0.18-10,2.1.2

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.