9

CVE-2020-27151

Exploit
An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KatacontainersKata Containers Version <= 1.11.3
KatacontainersKata Containers Version2.0.0 Updatealpha1
KatacontainersKata Containers Version2.0.0 Updatealpha2
KatacontainersKata Containers Version2.0.0 Updatealpha3
KatacontainersKata Containers Version2.0.0 Updaterc0
KatacontainersKata Containers Version2.0.0 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.681
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.