CVE-2021-3762
published 2022-03-03CVE-2021-3762: A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.51%
90.4th percentile
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | quay_claircore | >= 0 < 0.4.8 | 0.4.8 |
| github.com | quay_claircore | >= 0 < 1.1.0 | 1.1.0 |
| github.com | quay_claircore | >= 0.5.0 < 0.5.5 | 0.5.5 |
| github.com | quay_claircore | >= 1.0.0 < 1.1.0 | 1.1.0 |
| quay | claircore | — | — |
| redhat | clair | >= 0.4.6 < 0.4.8 | 0.4.8 |
| redhat | clair | >= 0.5.3 < 0.5.5 | 0.5.5 |
| redhat | quay | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered when Clair/ClairCore scans a crafted container image layer containing directory traversal sequences, resulting in arbitrary file writes on the filesystem. Monitor Clair scan activity for unexpected file creation outside expected paths. ↗
- →The attack vector is a malicious container image layer submitted for scanning. Inspect container image layers for path traversal sequences (e.g., '../') in filenames or archive entries before ingestion by ClairCore. ↗
- ·Only Red Hat Quay version 3.5.6 is affected. All previous released versions of Red Hat Quay are not affected. ↗
- ·In Red Hat Quay deployments, Clair runs as the 'nobody' user in an unprivileged container, which limits the impact to modification of non-sensitive files within that container — reducing the effective severity from Critical (ClairCore engine) to Important (Red Hat Quay product). ↗
- ·Red Hat Advanced Cluster Security and Quay.io are confirmed NOT affected by this vulnerability. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Path traversal in github.com/quay/claircore
osv·2022-07-15
CVE-2021-3762 Path traversal in github.com/quay/claircore
Path traversal in github.com/quay/claircore
A maliciously crafted RPM file can cause the Scanner.Scan function to write files with arbitrary contents to arbitrary locations on the local filestem.
OSV
Path traversal in claircore
osv·2022-03-04
CVE-2021-3762 [HIGH] Path traversal in claircore
Path traversal in claircore
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
GHSA
Path traversal in claircore
ghsa·2022-03-04
CVE-2021-3762 [HIGH] CWE-22 Path traversal in claircore
Path traversal in claircore
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
Red Hat
quay/claircore: directory traversal when scanning crafted container image layer allows for arbitrary file write
vendor_redhat·2021-09-28·CVSS 9.8
CVE-2021-3762 [CRITICAL] CWE-22 quay/claircore: directory traversal when scanning crafted container image layer allows for arbitrary file write
quay/claircore: directory traversal when scanning crafted container image layer allows for arbitrary file write
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
Statement: Only a single version of Red Hat Quay, 3.5.6 is affected by this vulnerability. All previous released versions of Red Ha
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2000795https://github.com/quay/clair/pull/1379https://github.com/quay/clair/pull/1380https://github.com/quay/claircore/commit/691f2023a1720a0579e688b69a2f4bfe1f4b7821https://github.com/quay/claircore/pull/478https://vulmon.com/exploitdetails?qidtp=maillist_oss_security&qid=d19fce9ede06e13dfb5630ece7f14f83https://bugzilla.redhat.com/show_bug.cgi?id=2000795https://github.com/quay/clair/pull/1379https://github.com/quay/clair/pull/1380https://github.com/quay/claircore/commit/691f2023a1720a0579e688b69a2f4bfe1f4b7821https://github.com/quay/claircore/pull/478https://vulmon.com/exploitdetails?qidtp=maillist_oss_security&qid=d19fce9ede06e13dfb5630ece7f14f83
2022-03-03
Published