CVE-2019-10144
published 2019-06-03CVE-2019-10144: rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities…
PriorityP431high7.7CVSS 3.1
AVLACLPRHUIRSCCHIHAH
EPSS
0.47%
37.7th percentile
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | rkt | <= 1.30.0 | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-53c8-4j57-m6p5: rkt through version 1
ghsa_unreviewed·2022-05-24
CVE-2019-10144 [HIGH] CWE-250 GHSA-53c8-4j57-m6p5: rkt through version 1
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.
OSV
CVE-2019-10144: rkt through version 1
osv·2019-06-03·CVSS 7.7
CVE-2019-10144 [HIGH] CVE-2019-10144: rkt through version 1
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capabilities during stage 2 (the actual environment in which the applications run). Compromised containers could exploit this flaw to access host resources.
No detection rules found.
No public exploits indexed.
Unit42
Breaking Out of rkt – 3 New Unpatched CVEs
blogs_unit42·2019-05-30·CVSS 8.6
CVE-2019-5736 [HIGH] Breaking Out of rkt – 3 New Unpatched CVEs
# Executive Summary
Back in February, I wrote a piece on the major runC vulnerability, CVE-2019-5736. The fundamental flaw behind this vulnerability affected most container runtimes, such as LXC and Apache Mesos. One container runtime which seemed to be unfazed was CoreOS rkt, on which I heard a lot back when I first started to get into containers. So naturally, I was intrigued to check out rkt’s architecture and see what they did differently, and I recently had some time to do so.
I ended up finding 3 other, unrelated vulnerabilities in rkt. These vulnerabilities allow an attacker to compromise the host when a rkt user executes the ‘rkt enter’ command (the equivalent of ‘docker exec’) into an attacker-controlled pod. They are currently unpatched.
### rkt
rkt is an open source containe
Unit42
Breaking Out of rkt – 3 New Unpatched CVEs
blogs_unit42·2019-05-30·CVSS 7.7
CVE-2019-10147 [HIGH] Breaking Out of rkt – 3 New Unpatched CVEs
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Breaking Out of rkt – 3 New Unpatched CVEs
Yuval Avrahami
Published: May 30, 2019
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
CVE-2019-10147
Docker. CVE-2019-10144. CVE-2019-10145
## Executive Summary
Back in February, I wrote a piece on the major runC vulnerability, CVE-2019-5736. The fundamental flaw behind this vulnerability affected most container runtimes, such as LXC and Apache Mesos. One container runtime which seemed to be unfazed was CoreOS rkt , on which I heard a lot back when I first started to get into containers. So naturally, I was intrigued to check out rkt’s architecture and see what they did differently, and I recently had some time to do so.
I ended up finding 3 other
Bugzilla
CVE-2019-10144 rkt: processes run with `rkt enter` are given all capabilities during stage 2 [fedora-all]
bugzilla·2019-05-31·CVSS 7.7
CVE-2019-10144 [HIGH] CVE-2019-10144 rkt: processes run with `rkt enter` are given all capabilities during stage 2 [fedora-all]
CVE-2019-10144 rkt: processes run with `rkt enter` are given all capabilities during stage 2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-10144 rkt: processes run with `rkt enter` are given all capabilities during stage 2
bugzilla·2019-05-20·CVSS 7.7
CVE-2019-10144 [HIGH] CVE-2019-10144 rkt: processes run with `rkt enter` are given all capabilities during stage 2
CVE-2019-10144 rkt: processes run with `rkt enter` are given all capabilities during stage 2
Processes run with `rkt enter` are given all capabilities during stage 2(the actual environment in which the applications run).
Reference:
https://coreos.com/rkt/docs/latest/devel/architecture.html#stage-2
Discussion:
Acknowledgments:
Name: Yuval Avrahami (Twistlock)
---
Created rkt tracking bugs for this issue:
Affects: fedora-all [bug 1715686]
---
External Reference:
https://www.twistlock.com/labs-blog/breaking-out-of-coresos-rkt-3-new-cves/
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
2019-06-03
Published