HIGH🇵🇱 Wersja polska

CVE-2020-27151

CVSS 8.8v3.1pub. 2020-12-07upd. 2024-11-21

An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Katacontainers Kata Containers

    APP
    Katacontainers
    2.0.0≤ 1.11.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-24834CRITICAL9.3PL ✓same product

Kata Containers: modyfikacja systemu plików VM umożliwia RCE jako root

CVE-2026-41326HIGH8.2same product

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine...

CVE-2026-24054HIGH8.8same product

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine...

CVE-2026-44210MEDIUM5.8same product

Kata Containers to projekt open source implementujący lekkie Virtual Machines działające jak kontenery. Wersje...

CVE-2020-28914HIGH7.1same vendor

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes ho...