CVE-2022-27652 Information
Jun 07, 2022
cve
Description
A flaw was found in cri-o where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Reference
https://github.com/cri-o/cri-o/security/advisories/GHSA-4hj2-r2pm-3hc6 https://bugzilla.redhat.com/show_bug.cgi?id=2066839
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.3
Share on: