CVE-2020-27534Medium· 5.3▾ SunlitPath Traversal in Moby builder
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.7%
util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.
github.com/moby/moby < 19.03.9github.com/docker/docker < 19.03.9Upgrade to a patched release:
github.com/moby/moby 19.03.9github.com/docker/docker 19.03.9Connected by shared product, vendor, weakness, or advisory.
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
CVE-2021-21284Medium· 6.8moby Access to remapped root allows privilege escalation to real root
CVE-2021-21285Medium· 6.5moby docker daemon crash during image pull of malicious image
CVE-2021-41091Medium· 5.9Moby (Docker Engine) Insufficiently restricted permissions on data directory
CVE-2024-23652Critical· 10.0BuildKit vulnerable to possible host system access from mount stub cleaner