Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20317
HistoryMay 24, 2019 - 11:10 a.m.

Directory Traversal

2019-05-2411:10:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.001

Percentile

35.2%

Docker is vulnerable to directory traversal. The daemon/archive.go does not perform archive operations on a frozen filesystem or from within a chroot, allowing an attacker to perform a symlink-exchange attack using the docker cp command that results in arbitrary read-write access to the host filesystem with root privileges.