Vulnerability Description
In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Portainer | Portainer | < 2.11.1 |
References
- https://github.com/portainer/agent/compare/2.11.0...2.11.1PatchThird Party Advisory
- https://github.com/portainer/agent/pull/225/commits/a66977c76043fcff4a8f69c4b659PatchThird Party Advisory
- https://github.com/portainer/portainer/issues/6420Issue TrackingThird Party Advisory
- https://www.portainer.io/blog/should-you-expose-portainer-or-agent-to-the-internVendor Advisory
- https://github.com/portainer/agent/compare/2.11.0...2.11.1PatchThird Party Advisory
- https://github.com/portainer/agent/pull/225/commits/a66977c76043fcff4a8f69c4b659PatchThird Party Advisory
- https://github.com/portainer/portainer/issues/6420Issue TrackingThird Party Advisory
- https://www.portainer.io/blog/should-you-expose-portainer-or-agent-to-the-internVendor Advisory
FAQ
What is CVE-2022-24961?
CVE-2022-24961 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.
How severe is CVE-2022-24961?
CVE-2022-24961 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-24961?
Check the references section above for vendor advisories and patch information. Affected products include: Portainer Portainer.