Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2022-0071
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hotdog Container Escape
Source: NVD (National Vulnerability Database)
Vulnerability Description
Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of the host, modify devices, or make syscalls that would otherwise be blocked.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
带着不必要的权限执行
Source: NVD (National Vulnerability Database)
Vulnerability Title
Hotdog 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hotdog是一组 OCI 挂钩。用于将 Log4j Hot Patch 注入容器。 Hotdog v1.0.2之前版本存在安全漏洞,该漏洞源于应用没有有效进行目标 JVM 进程的资源限制、设备限制或系统调用过滤器。攻击者利用该漏洞可以实现容器耗尽主机资源、修改设备或进行系统调用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Amazon Web ServicesHotdog unspecified ~ 1.0.2 -
II. Public POCs for CVE-2022-0071
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2022-0071
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2022-0071

No comments yet


Leave a comment