CVE-2021-23732
PoC —CVSS 3.1
9.0 critical
EPSS
2%p78
Published
()
Modified
Description
This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a position to execute any arbitrary OS commands on the host system.
- Vendors
- quobject
- Products
- docker-cli-js
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.