IBM Cloud Functions is affected by a security vulnerability in runc which could allow an attacker, authorized to run a process as root inside a container, to execute arbitrary commands with root privileges on the container’s host system.
CVEID: CVE-2019-5736
DESCRIPTION: Runc could allow a local attacker to execute arbitrary commands on the system, cause by the improper handling of system file descriptors when running containers. An attacker could exploit this vulnerability using a malicious container to overwrite the contents of the host runc binary and execute arbitrary commands with root privileges on the host system.
CVSS Base Score: 7.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156819> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
All versions of IBM Cloud Functions are impacted.
IBM Cloud Functions has been updated with a fix that addresses this vulnerability. This bulletin is for informational purposes only. There is no further action required for IBM Cloud Functions users.
CPE | Name | Operator | Version |
---|---|---|---|
ibm cloud functions | eq | any |