CVE-2021-41089

Related Vulnerabilities: CVE-2021-41089  

No description is available for this CVE.

Description

No description is available for this CVE.

Statement

In OpenShift Container Platform (OCP) and Migration Toolkit for Virtualization (MTV) some components bundle github.com/moby/moby, but successful exploitation requires using a specially crafted container, therefore impact to these components is LOW.

In OpenShift Container Platform (OCP) and Migration Toolkit for Virtualization (MTV) some components bundle github.com/moby/moby, but successful exploitation requires using a specially crafted container, therefore impact to these components is LOW.

Additional Information

  • Bugzilla 2008592: CVE-2021-41089 moby: `docker cp` allows unexpected chmod of host file
  • CWE-552: Files or Directories Accessible to External Parties
  • FAQ: Frequently asked questions about CVE-2021-41089