[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2021-1523 --- containerd

ID: oval:org.secpod.oval:def:1601462Date: (C)2021-07-26   (M)2024-02-08
Class: PATCHFamily: unix




A bug was discovered in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host"s filesystem. Changes to file permissions can deny access to the expected owner of the file or widen access to others. A flaw was found in containerd CRI plugin. Containers launched through containerd's CRI implementation that share the same image may receive incorrect environment variables, including values that are defined for other containers. The highest threat from this vulnerability is to data confidentiality.

Platform:
Amazon Linux AMI
Product:
containerd
Reference:
ALAS-2021-1523
CVE-2021-32760
CVE-2021-21334
CVE    2
CVE-2021-21334
CVE-2021-32760

© SecPod Technologies