10

CVE-2022-42150

Exploit
TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TinylabCloud Lab Version0.8 Updaterc2
TinylabCloud Lab Version1.1 Updaterc1
TinylabLinux Lab Version1.1 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://github.com/eBPF-Research/eBPF-Attack/blob/main/PoC.md#attack-requirements
Third Party Advisory
Exploit
https://github.com/tinyclub/cloud-lab/blob/d19ff92713685a7fb84b423dea6a184b25c378c9/configs/common/seccomp-profiles-default.json
Patch
https://github.com/tinyclub/linux-lab/issues/14
Issue Tracking
https://hackmd.io/%40UR9gnr32QymtmtZHnZceOw/ry428EZGo
https://www.usenix.org/conference/usenixsecurity23/presentation/he
Third Party Advisory
Exploit