 
                        We found results for “”
CVE-2021-41089
Good to know:
 
                                    Date: October 4, 2021
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using "docker cp" into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.
Language: Go
Severity Score
Related Resources (13)
Severity Score
Weakness Type (CWE)
Improper Preservation of Permissions
CWE-281Top Fix
 
                                    Upgrade Version
Upgrade to version github.com/docker/docker - v20.10.9;github.com/docker/docker - v20.10.9+incompatible;github.com/moby/moby - v20.10.9+incompatible
CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | LOCAL | 
| Attack Complexity (AC): | HIGH | 
| Privileges Required (PR): | LOW | 
| User Interaction (UI): | NONE | 
| Scope (S): | CHANGED | 
| Confidentiality (C): | LOW | 
| Integrity (I): | NONE | 
| Availability (A): | NONE | 
CVSS v2
| Base Score: |  | 
|---|---|
| Access Vector (AV): | LOCAL | 
| Access Complexity (AC): | MEDIUM | 
| Authentication (AU): | NONE | 
| Confidentiality (C): | PARTIAL | 
| Integrity (I): | PARTIAL | 
| Availability (A): | PARTIAL | 
| Additional information: | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

