Lucene search

K
redhatcveRedhat.comRH:CVE-2018-15664
HistoryMay 28, 2019 - 5:50 p.m.

CVE-2018-15664

2019-05-2817:50:14
redhat.com
access.redhat.com
48

EPSS

0.001

Percentile

35.2%

A flaw was discovered in the API endpoint behind the ‘docker cp’ command. The endpoint is vulnerable to a Time Of Check to Time Of Use (TOCTOU) vulnerability in the way it handles symbolic links inside a container. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

Mitigation

Stopping a container prior to running "docker cp" removes the TOCTOU vulnerability.