"value":"A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Other"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Apache",
"product":{
"product_data":[
{
"product_name":"Apache Mesos",
"version":{
"version_data":[
{
"version_value":"pre-1.4.x"
},
{
"version_value":"1.4.0 to 1.4.2"
},
{
"version_value":"1.5.0 to 1.5.2"
},
{
"version_value":"1.6.0 to 1.6.1"
},
{
"version_value":"1.7.0 to 1.7.1"
}
]
}
}
]
}
}
]
}
},
"references":{
"reference_data":[
{
"refsource":"MLIST",
"name":"[mesos-dev] 20190323 CVE-2019-0204: Some Mesos components can be overwritten making arbitrary code execution possible.",