Lucene search

K
cveApacheCVE-2019-0204
HistoryMar 25, 2019 - 10:29 p.m.

CVE-2019-0204

2019-03-2522:29:00
apache
web.nvd.nist.gov
61
In Wild
cve-2019-0204
docker image
root user
apache mesos
exploit
security vulnerability
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

57.6%

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

Affected configurations

Nvd
Vulners
Node
apachemesosRange1.4.01.4.3
OR
apachemesosRange1.5.01.5.3
OR
apachemesosRange1.6.01.6.2
OR
apachemesosRange1.7.01.7.2
OR
apachemesosMatch1.8.0dev
Node
redhatfuseMatch7.5.0
VendorProductVersionCPE
apachemesos*cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:*
apachemesos1.8.0cpe:2.3:a:apache:mesos:1.8.0:dev:*:*:*:*:*:*
redhatfuse7.5.0cpe:2.3:a:redhat:fuse:7.5.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Apache Mesos",
    "vendor": "Apache",
    "versions": [
      {
        "status": "affected",
        "version": "pre-1.4.x"
      },
      {
        "status": "affected",
        "version": "1.4.0 to 1.4.2"
      },
      {
        "status": "affected",
        "version": "1.5.0 to 1.5.2"
      },
      {
        "status": "affected",
        "version": "1.6.0 to 1.6.1"
      },
      {
        "status": "affected",
        "version": "1.7.0 to 1.7.1"
      }
    ]
  }
]

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

57.6%