First published: Sun Oct 29 2023(Updated: )
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
Credit: securities@openeuler.org
Affected Software | Affected Version | How to fix |
---|---|---|
openEuler iSulad | =2.0.8-20210518.144540 | |
openEuler iSulad | =2.0.18-10 | |
openEuler iSulad | =2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33635.
The severity of CVE-2021-33635 is critical with a severity score of 9.8.
Openeuler Isula versions 2.0.8-20210518.144540, 2.0.18-10, and 2.1.2 are affected.
The vulnerability CVE-2021-33635 can be exploited by pulling malicious images using isula pull, which allows attackers to execute arbitrary code.
To fix CVE-2021-33635, it is recommended to update Openeuler Isula to a version that is not affected by the vulnerability. Please refer to the provided references for more information.