PT-2022-10660 · Clair · Clair

Yanir Tsarimi

·

Published

2022-03-03

·

Updated

2023-01-30

·

CVE-2021-3762

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clair versions (affected versions not specified)
Description A directory traversal issue in the ClairCore engine allows an attacker to exploit the system by providing a crafted container image. When scanned by Clair, this can lead to arbitrary file write on the filesystem, potentially enabling remote code execution. Additionally, a maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-3762
GHSA-MQ47-6WWV-V79W
GO-2022-0346

Affected Products

Clair