CVE-2019-18837
—CVSS 3.1
8.6 high
EPSS
1%p71
Published
()
Modified
Description
An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.
- Vendors
- crun projectfedoraproject
- Products
- crun, fedora
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.