Source |
The Hacker News |
Identifiant |
8445309 |
Date de publication |
2024-02-01 01:30:00 (vue: 2024-01-31 21:14:32) |
Titre |
RunC Flaws Enable Container Escapes, Granting Attackers Host Access |
Texte |
Multiple security vulnerabilities have been disclosed in the runC command line tool that could be exploited by threat actors to escape the bounds of the container and stage follow-on attacks.
The vulnerabilities, tracked as CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653, have been collectively dubbed Leaky Vessels by cybersecurity vendor Snyk.
"These container
Multiple security vulnerabilities have been disclosed in the runC command line tool that could be exploited by threat actors to escape the bounds of the container and stage follow-on attacks.
The vulnerabilities, tracked as CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653, have been collectively dubbed Leaky Vessels by cybersecurity vendor Snyk.
"These container |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
2024 21626 23651 23652 23653 access actors attackers attacks been bounds collectively command container could cve cybersecurity disclosed dubbed leaky enable escape escapes exploited flaws follow granting have host line multiple runc security snyk stage these threat tool tracked vendor vessels by vulnerabilities |
Tags |
Tool
Vulnerability
Threat
|
Stories |
|
Move |
|