First published: Sun Oct 29 2023(Updated: )
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
Credit: securities@openeuler.org
Affected Software | Affected Version | How to fix |
---|---|---|
openEuler iSulad | =2.0.8-20210518.144540 | |
openEuler iSulad | =2.0.18-10 | |
openEuler iSulad | =2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33637 is a vulnerability that occurs when the isula export command is used to export a container to an image and the container is controlled by an attacker, allowing the attacker to escape the container.
The severity of CVE-2021-33637 is high with a CVSS score of 8.4.
Openeuler Isula versions 2.0.8-20210518.144540, 2.0.18-10, and 2.1.2 are affected by CVE-2021-33637.
To fix CVE-2021-33637, it is recommended to update Openeuler Isula to a patched version provided by the vendor. Refer to the references for more information.
You can find more information about CVE-2021-33637 in the references provided: [Reference 1](https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2023-1686), [Reference 2](https://gitee.com/src-openeuler/iSulad/pulls/627/files), [Reference 3](https://gitee.com/src-openeuler/iSulad/pulls/600/files).