Lucene search

K
cvelistRedhatCVELIST:CVE-2020-14298
HistoryJul 13, 2020 - 8:53 p.m.

CVE-2020-14298

2020-07-1320:53:26
redhat
www.cve.org
1

8.7 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.6%

The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version 1.13.1-108.git4ef4b30.el7, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected.

CNA Affected

[
  {
    "product": "Docker",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Affected version is 1.13.1-108.git4ef4b30.el7 shipped in Red Hat Enterprise Linux 7 Extras"
      }
    ]
  }
]