libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade runc | Jul 30, 2024 | Jun 1, 2016 |
| Docker | — | Upgrade to Docker v1.12.2 | May 4, 2017 | Jun 1, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/docker. | Oct 30, 2017 | Jun 1, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade docker-engine-selinuxUpgrade docker-engine | Nov 30, 2017 | Jun 1, 2016 |
| Oracle_linux | — | Upgrade docker-engine-selinuxUpgrade docker-engine | Jun 1, 2016 | Jun 1, 2016 |
| Redhat_linux | — | Upgrade docker-novolume-pluginUpgrade docker-lvm-pluginUpgrade dockerUpgrade docker-commonUpgrade docker-logrotateUpgrade docker-v1.10-migratorUpgrade docker-rhel-push-pluginUpgrade docker-selinuxUpgrade docker-forward-journald | Oct 6, 2017 | Jun 1, 2016 |
| Suse | — | Upgrade dockerUpgrade docker-bash-completionUpgrade docker-fish-completion | May 31, 2016 | Apr 26, 2016 |
| Ubuntu | — | Upgrade runc | Nov 19, 2024 | Jun 1, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub