Lucene search

K
redhatcveRedhat.comRH:CVE-2024-45310
HistorySep 03, 2024 - 11:41 a.m.

CVE-2024-45310

2024-09-0311:41:34
redhat.com
access.redhat.com
7
cve-2024-45310
security vulnerability
information

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

AI Score

3.9

Confidence

High

EPSS

0

Percentile

16.3%

A vulnerability was found in runc. A malicious attacker may create empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with os.MkdirAll. While this can be used to create empty files, existing files will not be truncated.

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

AI Score

3.9

Confidence

High

EPSS

0

Percentile

16.3%