← Back

CVE-2022-27652

nvd nist
Published: Apr 18, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 1.8 / Impact: 3.4
Source: NVD

Description

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

Affected (5)

Products: Kubernetes: Cri O · Fedoraproject: Fedora · Mobyproject: Moby · +1 more
Show all products
1 product
Cri O
1 product
Fedora
1 product
Moby
1 product
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 20.10.14
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.11
Version 4.0

References (4)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.