Back to search
CVE-2021-3762
Published: Mar 3, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
| Vendor | Product | Versions |
|---|---|---|
n/a | quay/claircore | affected Affects v0.4.6 and higher, v0.5.3 and higher | Fixedin claircore v0.4.8, v0.5.5. |
Weaknesses (CWE)
References
https://bugzilla.redhat.com/show_bug.cgi?id=2000795
x_refsource_MISC
https://github.com/quay/claircore/pull/478
x_refsource_MISC
https://github.com/quay/clair/pull/1379
x_refsource_MISC
https://github.com/quay/clair/pull/1380
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now