Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
CVSS Information
N/A
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
Docker和Moby 安全漏洞
Vulnerability Description
Docker是美国Docker公司的一款开源的应用容器引擎。该产品支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。Moby是一个开源项目,旨在推动软件的容器化,并帮助生态系统使容器技术主流化。 Docker和Moby存在安全漏洞。攻击者利用该漏洞可以修改主机硬件(打开/禁用蓝牙或调亮/调暗键盘)。
CVSS Information
N/A
Vulnerability Type
N/A