Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Docker Sandboxes read-only runtime mount writable through its shared-export alias
Vulnerability Description
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Docker Sandboxes 授权问题漏洞
Vulnerability Description
Docker Sandboxes是美国Docker公司的一个容器沙箱隔离环境。 Docker Sandboxes 0.35.0版本至0.38.0版本存在授权问题漏洞,该漏洞源于仅将运行时主机挂载的只读意图应用于客户机容器绑定,底层virtio-fs主机边缘授权被添加到沙箱策略共享允许列表且未设置访问模式,可能导致沙箱内非特权代码向只读挂载的主机目录写入数据。
CVSS Information
N/A
Vulnerability Type
N/A