GHSA-3fwx-pjgw-3558
MEDIUMCVE-2021-41091A bug was found in Moby (Docker Engine) where the data directory (typically /var/lib/docker) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and exe
- Affected
- >=0, <20.10.9+incompatible, >=0, <20.10.9+incompatible
- Fixed in
- 20.10.9
- Published
- 2024-01-31
- Source
- github