Apple

Containerization

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 16.09.2026 22:24:20
  • Zuletzt bearbeitet 18.09.2026 17:48:19

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization ve...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 22.01.2026 23:58:20
  • Zuletzt bearbeitet 27.01.2026 20:17:18

The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into...