Description
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-16998 | Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user is allowed to spawn new containers with critical capabilities such as SYS_MODULE, which can be used to take over the Docker host. |
References
| Link | Providers |
|---|---|
| https://github.com/portainer/portainer/issues/4105 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:12:08.497Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-24263
No data.
Status : Modified
Published: 2021-03-16T15:15:12.530
Modified: 2024-11-21T05:14:32.763
Link: CVE-2020-24263
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD