René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

196 lines
5.9 KiB
JSON

{
"id": "CVE-2020-2023",
"sourceIdentifier": "psirt@paloaltonetworks.com",
"published": "2020-06-10T18:15:11.280",
"lastModified": "2021-10-19T12:45:49.630",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions."
},
{
"lang": "es",
"value": "Kata Containers no restringe el acceso de los contenedores al dispositivo del sistema de archivos root del invitado. Los contenedores maliciosos pueden explotar esto para obtener la ejecuci\u00f3n del c\u00f3digo en el invitado y hacerse pasar por el agente de kata. Este problema afecta a: Kata Containers versiones 1.11 anteriores a 1.11.1; Kata Containers versiones 1.10 anteriores a 1.10.5; y Kata Containers versiones 1.9 y anteriores"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.0,
"impactScore": 3.7
},
{
"source": "psirt@paloaltonetworks.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 3.8,
"baseSeverity": "LOW"
},
"exploitabilityScore": 2.0,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.6
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
},
{
"source": "psirt@paloaltonetworks.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-250"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:katacontainers:runtime:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.9",
"matchCriteriaId": "0AB886E3-03F3-43FA-AE4F-092FA6246A31"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:katacontainers:runtime:*:*:*:*:*:*:*:*",
"versionStartIncluding": "1.10",
"versionEndExcluding": "1.10.5",
"matchCriteriaId": "FD1E8DE9-C5B6-4DA0-A5B2-A6C3B38DD2B6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:katacontainers:runtime:*:*:*:*:*:*:*:*",
"versionStartIncluding": "1.11",
"versionEndExcluding": "1.11.1",
"matchCriteriaId": "1358CC70-876F-4CA6-AC86-551883794212"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/kata-containers/agent/issues/791",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://github.com/kata-containers/agent/pull/792",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Patch"
]
},
{
"url": "https://github.com/kata-containers/runtime/issues/2488",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://github.com/kata-containers/runtime/pull/2477",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://github.com/kata-containers/runtime/pull/2487",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://github.com/kata-containers/runtime/releases/tag/1.10.5",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Release Notes",
"Third Party Advisory"
]
},
{
"url": "https://github.com/kata-containers/runtime/releases/tag/1.11.1",
"source": "psirt@paloaltonetworks.com",
"tags": [
"Release Notes",
"Third Party Advisory"
]
}
]
}