Record summary

CVE-2021-21284 has a selected CVSS score of 6.8 (medium).

Description

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/<remapping>" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 19.03.15affected
>= 20.0.0, < 20.10.3affected
GitHub AdvisoryBefore 19.3.15 · Fixed in 19.3.15affected
20.10.0-beta1 to < 20.10.3 · Fixed in 20.10.3affected

References

9