Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29294
HistoryFeb 08, 2021 - 6:36 a.m.

Arbitrary Path Injection

2021-02-0806:36:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
containernetworking
arbitrary path
binary execution
vulnerability
cni configuration

EPSS

0.001

Percentile

47.3%

github.com/containernetworking/cni is vulnerable to arbitrary path injection. A user is be able to change the type: field in a CNI configuration to an arbitrary path and could execute arbitrary binaries on a host.