CVE-2019-0204

CWE-2507 documents6 sources
Severity
7.8HIGH
EPSS
0.2%
top 60.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 13

Description

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDapache/mesos1.4.01.4.3+4
Mavenorg.apache.mesos:mesos1.5.01.5.3+3
CVEListV5apache/apache_mesos5 versions+4
NVDredhat/fuse7.5.0

🔴Vulnerability Details

3
GHSA
Docker image code execution with Apache Mesos2022-05-13
OSV
Docker image code execution with Apache Mesos2022-05-13
CVEList
CVE-2019-0204: A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command execu2019-03-25

📋Vendor Advisories

1
Red Hat
mesos: docker image code execution2019-03-23

💬Community

2
Bugzilla
CVE-2019-0204 mesos: docker image code execution2019-03-26
Bugzilla
CVE-2019-0204 mesos: docker image code execution [fedora-all]2019-03-26