6.3
CVSSv3

CVE-2021-41089

Published: 04/10/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.3 | Impact Score: 3.7 | Exploitability Score: 2
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mobyproject moby

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Synopsis Important: Red Hat Advanced Cluster Management 242 security updates and bug fixes Type/Severity Security Advisory: Important Topic Red Hat Advanced Cluster Management for Kubernetes 242 General Availabilityrelease images This update provides security fixes, fixes bugs, and updates the container imagesRed Hat Product Security ha ...
A bug was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permission changes for existing files in the host 2019s filesystem, widening access to others This bug does not directly allow files to be read, modified, or executed without an additional cooperating pr ...
No description is available for this CVE ...
A file permissions vulnerability was found in Moby (Docker Engine) Copying files by using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host's filesystem, which might lead to permissions escalation and allow an attacker access to restricted data (CVE-2021-41089) Moby is an open ...
A file permissions vulnerability was found in Moby (Docker Engine) Copying files by using into a specially-crafted container can result in Unix file permission changes for existing files in the host's filesystem, which might lead to permissions escalation and allow an attacker access to restricted data (CVE-2021-41089) Moby is an open-source pro ...
A file permissions vulnerability was found in Moby (Docker Engine) Copying files by using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host's filesystem, which might lead to permissions escalation and allow an attacker access to restricted data (CVE-2021-41089) Moby is an open ...
A bug was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others This bug does not directly allow files to be read, modified, or executed without an additional cooperating proc ...

Github Repositories

The vulnerabilities i've found

my_vulnerabilities 1 Cloud Native Projects 11 bitnami/laravel 111 [DONE] CVE-2021-21979: APP_KEY is fixed in docker image bitnami/laravel Timeline: 2021-02-23 Reported to bitnami 2021-02-24 Fixed 2021-02-24 CVE number assigned DONE 12 meshery 121 [DONE] CVE-2021-31856: A Sql Injection in Meshery githubcom/ssst0n3/CVE-2021-31856 Timeline: 2021-04-20 Discovered