漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Docker Sandboxes read-only runtime mount writable through its shared-export alias
Vulnerability Description
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Docker Sandboxes 授权问题漏洞
Vulnerability Description
Docker Sandboxes是美国Docker公司的一个容器沙箱隔离环境。 Docker Sandboxes 0.35.0版本至0.38.0版本存在授权问题漏洞,该漏洞源于仅将运行时主机挂载的只读意图应用于客户机容器绑定,底层virtio-fs主机边缘授权被添加到沙箱策略共享允许列表且未设置访问模式,可能导致沙箱内非特权代码向只读挂载的主机目录写入数据。
CVSS Information
N/A
Vulnerability Type
N/A