Skip to content

Bottlerocket GHSA-fw7f-8wr8-6987

Moderate
bcressey published GHSA-fw7f-8wr8-6987 Sep 18, 2020

Package

bottlerocket (bottlerocket)

Affected versions

< 1.0.0

Patched versions

1.0.0

Description

Host containers were run with the same process and mount labels as containers started by the orchestrator agent. This would allow malicious containers to modify files inside a host container, if they had access to those files through host volume mounts and the required permissions.

Our security guidance recommends limiting access to host volume mounts and against running privileged containers.

The Bottlerocket team thanks Stephen Breen of Atredis Partners for reporting this issue.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs