Files
CVEs-PoC/2021/CVE-2021-30465.md
T
2024-06-07 04:52:01 +00:00

38 lines
1.7 KiB
Markdown

### [CVE-2021-30465](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30465)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/43622283/awesome-cloud-native-security
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Lodestone-Team/safe_path_subset
- https://github.com/Metarget/awesome-cloud-native-security
- https://github.com/Metarget/metarget
- https://github.com/Srylax/safe-path
- https://github.com/UCloudDoc-Team/uk8s
- https://github.com/UCloudDocs/uk8s
- https://github.com/adavarski/HomeLab-Proxmox-k8s-DevSecOps-playground
- https://github.com/adavarski/HomeLab-k8s-DevSecOps-playground
- https://github.com/apps4uco/safe-path
- https://github.com/asa1997/topgear_test
- https://github.com/atesemre/awesome-cloud-native-security
- https://github.com/champtar/blog
- https://github.com/h4ckm310n/Container-Vulnerability-Exploit
- https://github.com/iridium-soda/container-escape-exploits
- https://github.com/kaosagnt/ansible-everyday
- https://github.com/magnologan/awesome-k8s-security
- https://github.com/reni2study/Cloud-Native-Security2
- https://github.com/superfish9/pt
- https://github.com/wllenyj/safe-path-rs