PT-2018-10808 · Apache · Docker Skeleton Runtime For Apache Openwhisk
Ory Segal
+1
·
Published
2018-07-23
·
Updated
2019-10-03
·
CVE-2018-11757
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Docker Skeleton Runtime for Apache OpenWhisk versions 1.3.0 and earlier
Description
The issue allows an attacker to replace the user function inside the container if the user code is vulnerable to code exploitation. This can occur in a Docker action that inherits the Docker tag openwhisk/dockerskeleton:1.3.0 or earlier.
Recommendations
For Docker Skeleton Runtime for Apache OpenWhisk versions 1.3.0 and earlier, consider updating to a newer version that contains a fix for this issue, although the specific fixed version is not provided in the available data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker Skeleton Runtime For Apache Openwhisk