Privilege Escalation Vulnerability in runc from OpenContainers
CVE-2023-27561
7HIGH
What is CVE-2023-27561?
The runc container runtime, specifically versions up to 1.1.4, exhibits a vulnerability characterized by incorrect access control that can potentially allow an attacker to escalate privileges. This issue arises when an attacker can create two containers with custom volume-mount configurations alongside the ability to execute custom images. The vulnerability also stems from a regression related to CVE-2019-19921, highlighting the need for careful configuration management in containerized environments.