MEDIUM🇬🇧 English

CVE-2023-38496

CVSS 6.1v3.1pub. 2023-07-25upd. 2024-11-21

Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
  • Lfprojects Apptainer

    APP
    Lfprojects
    1.2.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2023-30549HIGH7.1ten sam produkt

Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploit...

CVE-2025-65105MEDIUM4.5ten sam produkt

Apptainer to otwarta platforma konteneryzacji. W wersjach Apptainera poniżej 1.4.5 kontener może wyłączyć dwie...

CVE-2026-64849CRITICAL9.3⚠ KEVten sam vendor

MLflow is an open source AI engineering platform for agents, large language models, and machine learning model...

CVE-2026-2651CRITICAL9.0PL ✓ten sam vendor

MLflow: nieautoryzowany dostęp do endpointów multipart upload (RCE)

CVE-2026-2611CRITICAL9.6PL ✓ten sam vendor

MLflow: nieprawidłowa walidacja origin umożliwia RCE przez cross-origin request