Lucene search

K
amazonAmazonALAS-2022-1568
HistoryMar 01, 2022 - 6:04 p.m.

Medium: containerd

2022-03-0118:04:00
alas.aws.amazon.com
55
containerd
cri
bug
read-only access
kubernetes
security policy
cve-2022-23648

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.007

Percentile

80.1%

Issue Overview:

A bug was found in containerd where containers launched through containerdโ€™s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerdโ€™s CRI implementation. (CVE-2022-23648)

Affected Packages:

containerd

Issue Correction:
Run yum update containerd to update your system.

New Packages:

src:  
ย ย ย  containerd-1.4.6-8.12.amzn1.src  
  
x86_64:  
ย ย ย  containerd-debuginfo-1.4.6-8.12.amzn1.x86_64  
ย ย ย  containerd-1.4.6-8.12.amzn1.x86_64  
ย ย ย  containerd-stress-1.4.6-8.12.amzn1.x86_64  

Additional References

Red Hat: CVE-2022-23648

Mitre: CVE-2022-23648

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.007

Percentile

80.1%