CVE-2020-2024

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.04 % (13th)
0.04% Progress
Affected Products 1
Advisories 2

An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.

Weaknesses
CWE-59
Improper Link Resolution Before File Access ('Link Following')
CVE Status
PUBLISHED
CNA
Palo Alto Networks, Inc.
Published Date
2020-05-19 21:15:10
(4 years ago)
Updated Date
2020-05-21 17:13:02
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Katacontainers Runtime prior 1.11.0 version cpe:2.3:a:katacontainers:runtime < 1.11.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...