8.4

CVE-2021-33637

Export container in a malicious directory may cause process to be hijacked

When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpeneulerIsula Version2.0.8-20210518.144540
OpeneulerIsula Version2.0.18-10
OpeneulerIsula Version2.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.106
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2 4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
securities@openeuler.org 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

https://gitee.com/src-openeuler/iSulad/pulls/600/files
Patch
https://gitee.com/src-openeuler/iSulad/pulls/627/files
Patch
https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2023-1686
Vendor Advisory