#VU62796 Incorrect default permissions in CRI-O - CVE-2022-27652
Published: May 4, 2022 / Updated: May 12, 2022
CRI-O
CRI-O
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to containers are incorrectly started with non-empty default permissions within in Moby (Docker Engine). An attacker with access to programs with inheritable file capabilities can elevate those capabilities to the permitted set when execve(2) runs.