Vulnerability Description
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Clair | >= 0.4.6, < 0.4.8 |
| Redhat | Quay | 3.5.6 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2000795Issue TrackingPatchThird Party Advisory
- https://github.com/quay/clair/pull/1379PatchThird Party Advisory
- https://github.com/quay/clair/pull/1380PatchThird Party Advisory
- https://github.com/quay/claircore/commit/691f2023a1720a0579e688b69a2f4bfe1f4b782PatchThird Party Advisory
- https://github.com/quay/claircore/pull/478PatchThird Party Advisory
- https://vulmon.com/exploitdetails?qidtp=maillist_oss_security&qid=d19fce9ede06e1ExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2000795Issue TrackingPatchThird Party Advisory
- https://github.com/quay/clair/pull/1379PatchThird Party Advisory
- https://github.com/quay/clair/pull/1380PatchThird Party Advisory
- https://github.com/quay/claircore/commit/691f2023a1720a0579e688b69a2f4bfe1f4b782PatchThird Party Advisory
- https://github.com/quay/claircore/pull/478PatchThird Party Advisory
- https://vulmon.com/exploitdetails?qidtp=maillist_oss_security&qid=d19fce9ede06e1ExploitThird Party Advisory
FAQ
What is CVE-2021-3762?
CVE-2021-3762 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary f...
How severe is CVE-2021-3762?
CVE-2021-3762 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3762?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Clair, Redhat Quay.