You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
mend-bolt-for-githubbot
changed the title
CVE-2023-27561 (Medium) detected in github.com/opencontainers/runc-v1.0.3
CVE-2023-27561 (High) detected in github.com/opencontainers/runc-v1.0.3
Mar 8, 2023
mend-bolt-for-githubbot
changed the title
CVE-2023-27561 (High) detected in github.com/opencontainers/runc-v1.0.3
CVE-2023-27561 (High) detected in github.com/opencontainers/runc-v1.0.3 - autoclosed
Aug 2, 2023
✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
Uh oh!
There was an error while loading. Please reload this page.
CVE-2023-27561 - High Severity Vulnerability
CLI tool for spawning and running containers according to the OCI specification
Library home page: https://proxy.golang.org/github.com/opencontainers/runc/@v/v1.0.3.zip
Dependency Hierarchy:
Found in HEAD commit: b3ac62d12e3d43994ff7ad836e34da801ed665fb
Found in base branch: master
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Publish Date: 2023-03-03
URL: CVE-2023-27561
Base Score Metrics:
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: