First published: Sun Oct 29 2023(Updated: )
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
Credit: securities@openeuler.org
Affected Software | Affected Version | How to fix |
---|---|---|
openEuler iSulad | =2.0.8-20210518.144540 | |
openEuler iSulad | =2.0.18-10 | |
openEuler iSulad | =2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33638 is a vulnerability that occurs when the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, allowing the attacker to escape the container.
Openeuler Isula versions 2.0.8-20210518.144540, 2.0.18-10, and 2.1.2 are affected by CVE-2021-33638.
CVE-2021-33638 has a severity rating of 8.4, which is considered high.
To fix CVE-2021-33638, update Openeuler Isula to a version that is not affected by the vulnerability.
More information about CVE-2021-33638 can be found at the following references: [Link 1](https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2023-1686), [Link 2](https://gitee.com/src-openeuler/iSulad/pulls/627/files), [Link 3](https://gitee.com/src-openeuler/iSulad/pulls/600/files)