9

CVE-2020-27151

Exploit
An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Katacontainers ≫ Kata Containers Version <= 1.11.3
Katacontainers ≫ Kata Containers Version 2.0.0 Update alpha1
Katacontainers ≫ Kata Containers Version 2.0.0 Update alpha2
Katacontainers ≫ Kata Containers Version 2.0.0 Update alpha3
Katacontainers ≫ Kata Containers Version 2.0.0 Update rc0
Katacontainers ≫ Kata Containers Version 2.0.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.02% 0.784
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/kata-containers/runtime/releases/tag/1.11.5
Third Party Advisory
https://github.com/kata-containers/runtime/releases/tag/1.12.0
Third Party Advisory
https://bugs.launchpad.net/katacontainers.io/+bug/1878234
Third Party Advisory
Exploit
Issue Tracking
https://github.com/kata-containers/kata-containers/releases/tag/2.0.0
Third Party Advisory