Insecure dynamic library loading in Docker - CVE-2019-14271
Published: September 10, 2019 / Updated: March 16, 2023
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads NSS libraries in docker cp
in an insecure manner. A local attacker can pass a specially crafted library file to the application and execute arbitrary code on the system with elevated privileges.
Affected software
IBM Cloud Automation Manager
docker.io (Debian package)
docker (Alpine package)
How to mitigate CVE-2019-14271
docker.io (Debian package) - update to 18.09.1+dfsg1-7.1+deb10u1
docker (Alpine package) - update to 19.03.1-r1