Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36998
HistorySep 12, 2022 - 11:25 a.m.

Information Disclosure

2022-09-1211:25:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
github
moby
software
information disclosure
input validation
sensitive information
system

0.002 Low

EPSS

Percentile

56.3%

github.com/moby/moby is vulnerable to information disclosure. The vulnerability exists in the getUser function in oci_linux.go due to a lack of input validation, allowing an attacker to read sensitive information in the system.