Related Articles
All Mix →4 Ways Terrorist Profiling is Like Antivirus
Both can be bypassed by smart attackers who know they’re being profiled. Both have moderate success in catching less-dedicated attackers. You shouldn’t think either is…
Launching new domains view and enhanced policies
We’ve recently announced a new Domains page and major improvements to existing capabilities for setting custom attack surface policies. These updates bring unprecedented control over…
Remotely Managing Hyper-V in a Workgroup Environment
Table of Contents Server PowerShell Configuration Client Configuration Configuring Hyper-V Manager Authorization Workaround Summary A few weekends ago, I decided (because apparently I’m a masochist)…
Meet the team: Johanna Ydergård – Scaling the impact of ethical hackers
Table of Contents A broad and consultative beginning Being comfortable with uncertainty Narrowing down the focus to hackers and cybersecurity Diving into the world of…
API Attack Awareness: Broken Object Level Authorization (BOLA)
Table of Contents What is a BOLA Vulnerability? BOLA is Common, and the Consequences are Severe How a BOLA Vulnerability Could Play Out Mitigating BOLA:…


Impact
When using
--userns-remap, if the root user in the remapped namespace has access to the host filesystem they can modify files under/var/lib/docker/that cause writing files with extended privileges.Patches
Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
Credits
Maintainers would like to thank Alex Chapman for discovering the vulnerability; @awprice, @nathanburrell, @raulgomis, @chris-walz, @erin-jensby, @BassMatt, @mark-adams, @dbaxa for working on it and Zac Ellis for responsibly disclosing it to security@docker.com