CVE-2019-0204
HIGHApache Mesos <1.4.x, 1.4.0-1.4.2, 1.5.0-1.5.2, 1.6.0-1.6.1, 1.7.0-1...
Title source: llmDescription
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c%40%3Cdev.mesos.apache.org%3E
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/107605
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3892
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
38.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
Status
published
Products (4)
apache/mesos
1.8.0 dev
apache/mesos
1.4.0 - 1.4.3
org.apache.mesos/mesos
0 - 1.4.3Maven
redhat/fuse
7.5.0
Published
Mar 25, 2019
Tracked Since
Feb 18, 2026