CVE-2021-3762

CRITICAL

Clair 0.4.6-0.4.7 - Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

References (6)

Core 6
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2000795
Patch, Third Party Advisory x_refsource_misc
https://github.com/quay/claircore/pull/478
Patch, Third Party Advisory x_refsource_misc
https://github.com/quay/clair/pull/1379
Patch, Third Party Advisory x_refsource_misc
https://github.com/quay/clair/pull/1380

Scores

CVSS v3 9.8
EPSS 0.0866
EPSS Percentile 92.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (3)
quay/claircore 0 - 0.4.8Go
redhat/clair 0.4.6 - 0.4.8
redhat/quay 3.5.6
Published Mar 03, 2022
Tracked Since Feb 18, 2026