GHSA-32w9-2qpc-5f9v

    Dashboard / Vulnerabilities / GHSA-32w9-2qpc-5f9v

    GHSA-32w9-2qpc-5f9v

    Published: 13 May 2022Last Modified: 28 Nov 2024
    Aliases:

    Summary: Docker image code execution with Apache Mesos

    Details: A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

    Affected packages

    Package

    Name: org.apache.mesos:mesos

    Purl: pkg:maven/org.apache.mesos/mesos

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.4.3

    Affected versions

    0.10.0-incubating

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High