CVE-2020-2023

Published Jun 10, 2020

Last updated 3 years ago

Overview

Description
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.
Source
psirt@paloaltonetworks.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.3
Impact score
3.7
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.6
Impact score
6.4
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
psirt@paloaltonetworks.com
CWE-250

Social media

Hype score
Not currently trending

Configurations