Arbitrary File Override in Docker Engine
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Jul 8, 2024
Description
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Jul 8, 2024
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
References