Skip to content

Bottlerocket GHSA-xhm9-p6mw-357m

Moderate
bcressey published GHSA-xhm9-p6mw-357m Sep 18, 2020

Package

bottlerocket (bottlerocket)

Affected versions

< 1.0.0

Patched versions

1.0.0

Description

Containers started by the orchestrator agent that shared the host PID namespace could access the API socket through paths such as /proc/1/root. This would allow malicious containers to modify API settings, if they were running with UID 0 (root) or GID 274 (api), even if host volume mounts were not in use.

Our security guidance recommends against running privileged containers and against running containers as UID 0.

The Bottlerocket team thanks Stephen Breen of Atredis Partners for reporting this issue.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs