CVE Database
/

CVE-2019-0204

Back to search

CVE-2019-0204

Published: Mar 25, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

VendorProductVersions

Apache

Apache Mesos

affected
pre-1.4.x
affected
1.4.0 to 1.4.2
affected
1.5.0 to 1.5.2
affected
1.6.0 to 1.6.1
affected
1.7.0 to 1.7.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now