[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2NITRO-ENCLAVES-2021-004 --- docker

ID: oval:org.secpod.oval:def:1700784Date: (C)2021-12-14   (M)2023-12-20
Class: PATCHFamily: unix




A flaw was discovered in the API endpoint behind the #39;docker cp#39; command. The endpoint is vulnerable to a Time Of Check to Time Of Use vulnerability in the way it handles symbolic links inside a container. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container

Platform:
Amazon Linux 2
Product:
docker
Reference:
ALAS2NITRO-ENCLAVES-2021-004
CVE-2018-15664
CVE    1
CVE-2018-15664
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:docker:docker

© SecPod Technologies