PT-2019-6301 · Portainer · Portainer
Publicado
2019-09-23
·
Atualizado
2020-08-24
·
CVE-2019-16877
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Portainer versions prior to 1.22.1
Description
The issue is related to insufficient authorization procedure in the container management platform, which can be exploited by a remote attacker to gain full access to the host's file system through the host management API.
Recommendations
For versions prior to 1.22.1, update to version 1.22.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the host management API until a patch is available.
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Portainer