CVE-2020-2023
- EPSS 1.51%
- Published 10.06.2020 18:15:11
- Last modified 21.11.2024 05:24:28
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 version...
CVE-2020-2026
- EPSS 0.21%
- Published 10.06.2020 18:15:11
- Last modified 21.11.2024 05:24:29
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for cod...
CVE-2020-2024
- EPSS 0.12%
- Published 19.05.2020 21:15:10
- Last modified 21.11.2024 05:24:28
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentia...
CVE-2020-2025
- EPSS 0.05%
- Published 19.05.2020 21:15:10
- Last modified 21.11.2024 05:24:29
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the s...