4.6
CVSSv2

CVE-2020-2023

Published: 10/06/2020 Updated: 19/10/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.3 | Impact Score: 3.7 | Exploitability Score: 2
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and previous versions versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

katacontainers runtime

Github Repositories

kata-cve-2020-2023-poc 1 Reproduce Environment Note: The environment needs support KVM githubcom/ssst0n3/docker_archive/tree/branch_ubuntu-2004_docker-ce-190311_containerdio-149_kata-1110 $ git clone githubcom/ssst0n3/docker_archivegit $ cd docker_archive $ git checkout branch_ubuntu-2004_docker-ce-190311_containerdio-149_kata-1110 $ docker