One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 8105062
Date de publication 2022-11-19 01:15:13 (vue: 2022-11-19 07:06:57)
Titre CVE-2022-41939
Texte knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or compromised third-party buildpack could expose their registry credentials or local docker socket to a malicious `lifecycle` container. This issues has been patched in PR #1442, and is part of release 1.8.1. This issue only affects users who are using function buildpacks from third-parties; pinning the builder image to a specific content-hash with a valid `lifecycle` image will also mitigate the attack.
Envoyé Oui
Condensat #1442 2022 41939 `lifecycle` affects also are attack been builder buildpack buildpacks cli client compromised container content could credentials cve deployment dev/func developers development docker enabling expose from function functions has hash image issue issues knative kubernetes library local malicious mitigate only part parties; party patched pinning registry release socket specific third users using valid who will
Tags
Stories Uber
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: