10

CVE-2022-42150

Exploit
TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tinylab ≫ Cloud Lab Version 0.8 Update rc2
Tinylab ≫ Cloud Lab Version 1.1 Update rc1
Tinylab ≫ Linux Lab Version 1.1 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://github.com/eBPF-Research/eBPF-Attack/blob/main/PoC.md#attack-requirements
Third Party Advisory
Exploit
https://github.com/tinyclub/cloud-lab/blob/d19ff92713685a7fb84b423dea6a184b25c378c9/configs/common/seccomp-profiles-default.json
Patch
https://github.com/tinyclub/linux-lab/issues/14
Issue Tracking
https://hackmd.io/%40UR9gnr32QymtmtZHnZceOw/ry428EZGo
https://www.usenix.org/conference/usenixsecurity23/presentation/he
Third Party Advisory
Exploit