Vulnerability Name:

CVE-2021-30465 (CCN-202132)

Assigned:2021-05-18
Published:2021-05-18
Updated:2023-03-27
Summary:Open Container Initiative runc could allow a remote authenticated attacker to bypass security restrictions, caused by a symlink exchange attack. By sending a specially-crafted request, an attacker could exploit this vulnerability to allow host filesystem being bind-mounted into the container.
CVSS v3 Severity:8.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
7.4 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)
6.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): Low
Availibility (A): None
7.5 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.2 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:S/C:C/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2021-30465

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Issue Tracking
cve@mitre.org

Source: XF
Type: UNKNOWN
opencontainers-cve202130465-sec-bypass(202132)

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Release Notes, Third Party Advisory
cve@mitre.org

Source: CCN
Type: runc GIT Repository
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: UNKNOWN
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: oss-sec Mailing List, Wed, 19 May 2021 20:00:33 +1000
CVE-2021-30465: runc <1.0.0-rc95 vulnerable to symlink-exchange attack

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: CCN
Type: IBM Security Bulletin 6599703 (Db2 On Openshift)
Multiple vulnerabilities affect IBM Db2 On Openshift and IBM Db2 and Db2 Warehouse on Cloud Pak for Data

Source: CCN
Type: IBM Security Bulletin 6830587 (MQ Operator)
IBM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from containerd, gnupg2, runc and IBM WebSphere Application Server Liberty

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-30465

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7865
    P
    runc-1.1.5-150000.41.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:95287
    P
    Security update for permissions (Important)
    2022-08-03
    oval:org.opensuse.security:def:3797
    P
    Security update for gimp (Moderate)
    2022-08-01
    oval:org.opensuse.security:def:3794
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:95416
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:3249
    P
    libruby2_1-2_1-2.1.9-18.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3804
    P
    tcpdump-4.9.2-14.14.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3801
    P
    sysvinit-tools-2.88+-101.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94710
    P
    libsoup-2_4-1-2.74.2-150400.1.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94713
    P
    libsqlite3-0-3.36.0-3.12.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94879
    P
    runc-1.0.3-27.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6056
    P
    Security update for kernel-firmware (Moderate)
    2022-05-25
    oval:org.opensuse.security:def:100061
    P
    (Moderate)
    2022-04-01
    oval:org.opensuse.security:def:99750
    P
    (Moderate)
    2022-02-21
    oval:org.opensuse.security:def:102000
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Critical)
    2022-02-16
    oval:org.opensuse.security:def:99478
    P
    (Important)
    2022-01-25
    oval:org.opensuse.security:def:113413
    P
    runc-1.0.2-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99157
    P
    (Moderate)
    2021-11-04
    oval:org.opensuse.security:def:111104
    P
    Security update for containerd, docker, runc (Important)
    2021-10-31
    oval:org.opensuse.security:def:64886
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:106440
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:9602
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:92012
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:66957
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:93108
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:105847
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:10165
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:92402
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:99688
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:101426
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:6209
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:69551
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:93582
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:106727
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:76025
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:92800
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:100341
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:111761
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:103020
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:117606
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:8851
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:69941
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:93980
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:93268
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:108795
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:101681
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:106042
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:9411
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:70492
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:94403
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:99551
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:64893
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:42132
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:9801
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:92207
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:99153
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:5868
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:67298
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:989
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:106241
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:10352
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:92601
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:100005
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:102129
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:8664
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:69742
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:93766
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:98962
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:42231
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:108092
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:76366
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:100670
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:105652
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:9046
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:70305
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:94192
    P
    (Important)
    2021-10-25
    oval:org.opensuse.security:def:99352
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:20653
    P
    Security update for containerd, docker, runc (Important)
    2021-10-12
    oval:org.opensuse.security:def:49124
    P
    Security update for containerd, docker, runc (Important)
    2021-10-12
    oval:org.opensuse.security:def:106818
    P
    runc-1.0.2-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:99677
    P
    (Low)
    2021-09-07
    oval:org.opensuse.security:def:99985
    P
    (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:111579
    P
    Security update for containerd, docker, runc (Important)
    2021-07-10
    oval:org.opensuse.security:def:111437
    P
    Security update for containerd, docker, runc (Important)
    2021-06-16
    oval:org.opensuse.security:def:75896
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:92727
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:100294
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:103019
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:117603
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:8782
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:69868
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:93961
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:99088
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:108666
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:93232
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:101678
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:9346
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:70419
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:94384
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:64890
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:42090
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:9728
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:92138
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:5739
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:67145
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:10279
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:92528
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:99959
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:8603
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:69669
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:93746
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:98893
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:108089
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:76213
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:92926
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:100623
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:8977
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:70240
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:94172
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:99279
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:93411
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:64883
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:9529
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:91943
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:66828
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:93079
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:10100
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:92329
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:99646
    P
    (Important)
    2021-06-11
    oval:org.opensuse.security:def:97064
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:101423
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:69486
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:93568
    P
    (Important)
    2021-06-11
    oval:com.redhat.rhsa:def:20212370
    P
    RHSA-2021:2370: container-tools:3.0 security update (Important)
    2021-06-10
    oval:com.redhat.rhsa:def:20212371
    P
    RHSA-2021:2371: container-tools:rhel8 security update (Important)
    2021-06-10
    oval:com.redhat.rhsa:def:20212291
    P
    RHSA-2021:2291: container-tools:2.0 security update (Important)
    2021-06-08
    oval:org.opensuse.security:def:49122
    P
    Security update for runc (Important)
    2021-06-08
    oval:org.opensuse.security:def:20651
    P
    Security update for runc (Important)
    2021-06-08
    BACK