Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.
CVSS Information
N/A
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
rkt 权限许可和访问控制问题漏洞
Vulnerability Description
rkt是一款用于在Linux上运行应用程序容器的命令行界面。 rkt 1.30.0及之前的版本中存在安全漏洞,该漏洞源于程序没有隔离容器中的进程。攻击者可利用该漏洞访问资源。
CVSS Information
N/A
Vulnerability Type
N/A