CVE-2021-29136
published 2021-04-06CVE-2021-29136: Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.34%
26.8th percentile
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | umoci | < umoci 0.4.7+ds-1 (bookworm) | umoci 0.4.7+ds-1 (bookworm) |
| github.com | opencontainers_umoci | >= 0 < 0.4.7 | 0.4.7 |
| linuxfoundation | umoci | < 0.4.7 | 0.4.7 |
| linuxfoundation | umoci | >= 0 < 0.4.7+ds-1 | 0.4.7+ds-1 |
| linuxfoundation | umoci | >= 0 < 0.4.7+ds-1 | 0.4.7+ds-1 |
| linuxfoundation | umoci | >= 0 < 0.4.7+ds-1 | 0.4.7+ds-1 |
| linuxfoundation | umoci | >= 0 < 0.4.7+ds-1 | 0.4.7+ds-1 |
| sylabs | singularity | < 3.7.3 | 3.7.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper input validation in umoci in github.com/opencontainers/umoci
osv·2024-08-21
CVE-2021-29136 Improper input validation in umoci in github.com/opencontainers/umoci
Improper input validation in umoci in github.com/opencontainers/umoci
Improper input validation in umoci in github.com/opencontainers/umoci
OSV
Improper input validation in umoci
osv·2022-02-15
CVE-2021-29136 [MEDIUM] Improper input validation in umoci
Improper input validation in umoci
### Impact
umoci 0.4.6 and earlier can be tricked into modifying host files by
creating a malicious layer that has a symlink with the name "." (or
"/"). Because umoci deletes inodes if they change types, this results in
the rootfs directory being replaced with an attacker-controlled symlink.
Subsequent image layers will then be applied on top of the target of the
symlink (which could be any directory on the host filesystem the user
running umoci has access to).
While umoci does have defences against symlink-based attacks, they are
all implemented by resolving things relative to the rootfs directory --
if the rootfs itself is a symlink, umoci resolves it first.
This vulnerability affects both "umoci unpack" and "umoci raw unpack".
### Patches
This iss
GHSA
Improper input validation in umoci
ghsa·2022-02-15
CVE-2021-29136 [MEDIUM] CWE-20 Improper input validation in umoci
Improper input validation in umoci
### Impact
umoci 0.4.6 and earlier can be tricked into modifying host files by
creating a malicious layer that has a symlink with the name "." (or
"/"). Because umoci deletes inodes if they change types, this results in
the rootfs directory being replaced with an attacker-controlled symlink.
Subsequent image layers will then be applied on top of the target of the
symlink (which could be any directory on the host filesystem the user
running umoci has access to).
While umoci does have defences against symlink-based attacks, they are
all implemented by resolving things relative to the rootfs directory --
if the rootfs itself is a symlink, umoci resolves it first.
This vulnerability affects both "umoci unpack" and "umoci raw unpack".
### Patches
This iss
OSV
CVE-2021-29136: Open Container Initiative umoci before 0
osv·2021-04-06·CVSS 5.5
CVE-2021-29136 [MEDIUM] CVE-2021-29136: Open Container Initiative umoci before 0
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
Debian
CVE-2021-29136: umoci - Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbit...
vendor_debian·2021·CVSS 5.5
CVE-2021-29136 [MEDIUM] CVE-2021-29136: umoci - Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbit...
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
Scope: local
bookworm: resolved (fixed in 0.4.7+ds-1)
bullseye: resolved (fixed in 0.4.7+ds-1)
forky: resolved (fixed in 0.4.7+ds-1)
sid: resolved (fixed in 0.4.7+ds-1)
trixie: resolved (fixed in 0.4.7+ds-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/04/06/2https://github.com/opencontainers/umoci/commit/d9efc31daf2206f7d3fdb839863cf7a576a2eb57https://github.com/opencontainers/umoci/security/advisories/GHSA-9m95-8hx6-7p9vhttp://www.openwall.com/lists/oss-security/2021/04/06/2https://github.com/opencontainers/umoci/commit/d9efc31daf2206f7d3fdb839863cf7a576a2eb57https://github.com/opencontainers/umoci/security/advisories/GHSA-9m95-8hx6-7p9v
2021-04-06
Published