MEDIUM🇵🇱 Wersja polska

CVE-2023-38496

CVSS 6.1v3.1pub. 2023-07-25upd. 2024-11-21

Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
  • Lfprojects Apptainer

    APP
    Lfprojects
    1.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2023-30549HIGH7.1same product

Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploit...

CVE-2025-65105MEDIUM4.5same product

Apptainer to otwarta platforma konteneryzacji. W wersjach Apptainera poniżej 1.4.5 kontener może wyłączyć dwie...

CVE-2026-64849CRITICAL9.3⚠ KEVsame vendor

MLflow is an open source AI engineering platform for agents, large language models, and machine learning model...

CVE-2026-2651CRITICAL9.0PL ✓same vendor

MLflow: nieautoryzowany dostęp do endpointów multipart upload (RCE)

CVE-2026-2611CRITICAL9.6PL ✓same vendor

MLflow: nieprawidłowa walidacja origin umożliwia RCE przez cross-origin request