CVE-2021-3762: Path Traversal
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
Other sources
A vulnerability in Clair allows overwriting an arbitrary file anywhere in the filesystem, when scanning a malicious Docker layer. In most if not all instances this could lead to remote code execution on the Clair scanner instance.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3762?
CVE-2021-3762 is a directory traversal vulnerability found in the ClairCore engine of Clair.
How can an attacker exploit CVE-2021-3762?
An attacker can exploit CVE-2021-3762 by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
What is the severity of CVE-2021-3762?
CVE-2021-3762 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-3762?
The affected software versions are Quay/ClairCore 0.5.5 (up to exclusive), Quay/ClairCore 0.4.8 (up to exclusive), Redhat Clair (version 0.4.6 to 0.4.8), Redhat Clair (version 0.5.3 to 0.5.5), and Redhat Quay 3.5.6 (exactly).
How can I fix CVE-2021-3762?
To fix CVE-2021-3762, update the affected software to the recommended versions: Quay/ClairCore 0.5.5 or Quay/ClairCore 0.4.8.