CVE-2023-27561

ADVISORY - github

Summary

runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

EPSS Score: 0.00126 (0.327)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Use of Incorrectly-Resolved Name or Reference

ADVISORY - github

Use of Incorrectly-Resolved Name or Reference

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Use of Incorrectly-Resolved Name or Reference

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Improper Resolution of Path Equivalence


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in