ALASECS-2023-013

Related Vulnerabilities: CVE-2022-36109   CVE-2022-37708  

A flaw was found in Moby. This flaw allows an attacker to bypass primary group restrictions due to a flaw in the supplementary group access setup. (CVE-2022-36109) Docker version 20.10.15, build fd82621 is vulnerable to Insecure Permissions. Unauthorized users outside the Docker container can access any files within the Docker container. (CVE-2022-37708)

ALASECS-2023-013


Amazon Linux 2 Security Advisory: ALASECS-2023-013
Advisory Release Date: 2023-10-18 22:01 Pacific
Advisory Updated Date: 2023-10-19 21:47 Pacific
Severity: Medium

Issue Overview:

A flaw was found in Moby. This flaw allows an attacker to bypass primary group restrictions due to a flaw in the supplementary group access setup. (CVE-2022-36109)

Docker version 20.10.15, build fd82621 is vulnerable to Insecure Permissions. Unauthorized users outside the Docker container can access any files within the Docker container. (CVE-2022-37708)


Affected Packages:

docker


Issue Correction:
Run yum update docker to update your system.

New Packages:
aarch64:
    docker-20.10.22-1.amzn2.0.1.aarch64
    docker-debuginfo-20.10.22-1.amzn2.0.1.aarch64

src:
    docker-20.10.22-1.amzn2.0.1.src

x86_64:
    docker-20.10.22-1.amzn2.0.1.x86_64
    docker-debuginfo-20.10.22-1.amzn2.0.1.x86_64