mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-25 12:44:05 +02:00
38 lines
1.7 KiB
Markdown
38 lines
1.7 KiB
Markdown
### [CVE-2021-30465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30465)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/43622283/awesome-cloud-native-security
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/Lodestone-Team/safe_path_subset
|
|
- https://github.com/Metarget/awesome-cloud-native-security
|
|
- https://github.com/Metarget/metarget
|
|
- https://github.com/Srylax/safe-path
|
|
- https://github.com/UCloudDoc-Team/uk8s
|
|
- https://github.com/UCloudDocs/uk8s
|
|
- https://github.com/adavarski/HomeLab-Proxmox-k8s-DevSecOps-playground
|
|
- https://github.com/adavarski/HomeLab-k8s-DevSecOps-playground
|
|
- https://github.com/apps4uco/safe-path
|
|
- https://github.com/asa1997/topgear_test
|
|
- https://github.com/atesemre/awesome-cloud-native-security
|
|
- https://github.com/champtar/blog
|
|
- https://github.com/h4ckm310n/Container-Vulnerability-Exploit
|
|
- https://github.com/iridium-soda/container-escape-exploits
|
|
- https://github.com/kaosagnt/ansible-everyday
|
|
- https://github.com/magnologan/awesome-k8s-security
|
|
- https://github.com/reni2study/Cloud-Native-Security2
|
|
- https://github.com/superfish9/pt
|
|
- https://github.com/wllenyj/safe-path-rs
|
|
|