CVE-2022-36109
published 2022-09-09CVE-2022-36109: Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are…
PriorityP335medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.81%
52.2th percentile
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `"USER $USERNAME"` Dockerfile instruction. Instead by calling `ENTRYPOINT ["su", "-", "user"]` the supplementary groups will be set up properly.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | docker.io | < docker.io 20.10.19+dfsg1-1 (bookworm) | docker.io 20.10.19+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | containerd_containerd | >= 0 < 1.5.18 | 1.5.18 |
| github.com | containerd_containerd | >= 1.6.0 < 1.6.18 | 1.6.18 |
| github.com | docker_docker | >= 0 < 20.10.18 | 20.10.18 |
| github.com | docker_docker | >= 0 < 20.10.18+incompatible | 20.10.18+incompatible |
| moby | moby | < 20.10.18 | 20.10.18 |
| mobyproject | moby | < 20.10.18 | 20.10.18 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
ghsa7.1HIGH
osv7.1HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
moby: supplementary groups mishandling
vendor_redhat·2022-09-15·CVSS 5.3
CVE-2022-36109 [MEDIUM] moby: supplementary groups mishandling
moby: supplementary groups mishandling
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `"USER $USERNAME"` Dockerfile instruction. Instead by c
Debian
CVE-2022-36109: docker.io - Moby is an open-source project created by Docker to enable software containeriza...
vendor_debian·2022·CVSS 5.3
CVE-2022-36109 [MEDIUM] CVE-2022-36109: docker.io - Moby is an open-source project created by Docker to enable software containeriza...
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `"USER $USERNAME"` Dockerfile instruction. Instead by calling `ENTRYPOINT ["su", "-", "user"]`
OSV
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions in github.com/docker/docker
osv·2024-08-21
CVE-2022-36109 Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions in github.com/docker/docker
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions in github.com/docker/docker
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions in github.com/docker/docker
OSV
Supplementary groups are not set up properly in github.com/containerd/containerd
osv·2023-02-16·CVSS 7.1
CVE-2023-25173 [HIGH] Supplementary groups are not set up properly in github.com/containerd/containerd
Supplementary groups are not set up properly in github.com/containerd/containerd
### Impact
A bug was found in containerd where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.
Downstream applications that use the containerd client library may be affected as well.
### Patches
This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that
GHSA
Supplementary groups are not set up properly in github.com/containerd/containerd
ghsa·2023-02-16·CVSS 7.1
CVE-2023-25173 [HIGH] CWE-269 Supplementary groups are not set up properly in github.com/containerd/containerd
Supplementary groups are not set up properly in github.com/containerd/containerd
### Impact
A bug was found in containerd where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.
Downstream applications that use the containerd client library may be affected as well.
### Patches
This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that
GHSA
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
ghsa·2022-09-16
CVE-2022-36109 [MEDIUM] CWE-863 Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Users should update to this version when it is available. Running containers should be stopped and restarted for the permissions to be fixed.
OSV
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
osv·2022-09-16
CVE-2022-36109 [MEDIUM] Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Users should update to this version when it is available. Running containers should be stopped and restarted for the permissions to be fixed.
OSV
CVE-2022-36109: Moby is an open-source project created by Docker to enable software containerization
osv·2022-09-09·CVSS 6.3
CVE-2022-36109 [MEDIUM] CVE-2022-36109: Moby is an open-source project created by Docker to enable software containerization
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `"USER $USERNAME"` Dockerfile instruction. Instead by calling `ENTRYPOINT ["su", "-", "user"]`
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/moby/moby/commit/de7af816e76a7fd3fbf06bffa6832959289fba32https://github.com/moby/moby/releases/tag/v20.10.18https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4https://lists.fedoraproject.org/archives/list/[email protected]/message/O7JL2QA3RB732MLJ3RMUXB3IB7AA22YUhttps://lists.fedoraproject.org/archives/list/[email protected]/message/RQQ4E3JBXVR3VK5FIZVJ3QS2TAOOXXTQhttps://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigationhttps://github.com/moby/moby/commit/de7af816e76a7fd3fbf06bffa6832959289fba32https://github.com/moby/moby/releases/tag/v20.10.18https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O7JL2QA3RB732MLJ3RMUXB3IB7AA22YU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQQ4E3JBXVR3VK5FIZVJ3QS2TAOOXXTQ/
2022-09-09
Published