icon

We found results for “

CVE-2019-10145

Date: June 3, 2019

rkt through version 1.30.0 does not isolate processes in containers that are run with "rkt enter". Processes run with "rkt enter" do not have seccomp filtering during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.

Severity Score

Severity Score

Weakness Type (CWE)

Missing Authorization

CWE-862

Execution with Unnecessary Privileges

CWE-250

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

CVSS v2

Base Score:
Access Vector (AV): LOCAL
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): COMPLETE
Integrity (I): COMPLETE
Availability (A): COMPLETE
Additional information:

Do you need more information?

Contact Us