Skip to content

docker CVE-2021-21284

Low
tjkirch published GHSA-9hr9-47xc-fjgg Mar 2, 2021

Package

docker (bottlerocket)

Affected versions

< 1.0.6

Patched versions

1.0.6

Description

When using --userns-remap, if the root user in the remapped namespace has access to the host filesystem they can modify files under /var/lib/docker/<remapping> that cause writing files with extended privileges.

GHSA-7452-xqpj-6rpc

Severity

Low

CVE ID

CVE-2021-21284

Weaknesses

No CWEs