An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade buildah | Aug 22, 2024 | Mar 26, 2021 |
| Debian | — | Upgrade golang-github-appc-cni | Jul 30, 2024 | Mar 26, 2021 |
| Dell Powerstore Dsa2023366 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 5, 2023 |
| Redhat Openshift | — | Upgrade windows-machine-config-rhel8-operator | Aug 9, 2021 | Feb 5, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 26, 2021 |
| Suse | — | Upgrade cni-pluginsUpgrade buildahUpgrade libgpg-error-devel-32bitUpgrade libgpg-error-develUpgrade cniUpgrade libgpg-error0Upgrade libgpg-error0-32bit | Mar 9, 2022 | Mar 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub