Lucene search

K
osvGoogleOSV:USN-5103-1
HistoryOct 04, 2021 - 10:48 p.m.

docker.io vulnerability

2021-10-0422:48:39
Google
osv.dev
11

6.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.5%

Lei Wang and Ruizhi Xiao discovered that the Moby Docker engine in
Docker incorrectly allowed the docker cp command to make permissions
changes in the host filesystem in some situations. A local attacker
could possibly use to this to expose sensitive information or gain
administrative privileges.