GHSA-xjqr-g762-pxwp
Dashboard / Vulnerabilities / GHSA-xjqr-g762-pxwp
GHSA-xjqr-g762-pxwp
Summary: containernetworking/cni improper limitation of path name
Details: An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. ### Specific Go Packages Affected github.com/containernetworking/cni/pkg/invoke
References: https://nvd.nist.gov/vuln/detail/CVE-2021-20206, https://github.com/containernetworking/cni/pull/808, https://bugzilla.redhat.com/show_bug.cgi?id=1919391, https://github.com/containernetworking/cni, https://pkg.go.dev/vuln/GO-2022-0230, https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINERNETWORKINGCNIPKGINVOKE-1070549
Affected packages
Package
Name: github.com/containernetworking/cni
Purl: pkg:golang/github.com/containernetworking/cni
Affected ranges
Type: SEMVER
Events:
