CVE-2024-41228
HIGHAliyunContainerService pouch <1.3.1 - Privilege Escalation
Title source: llmDescription
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
References (1)
Core 1
Core References
Various Sources
https://gist.github.com/cafan/68ed2d065a4b9c1c37c70a18077ad27b
Scores
CVSS v3
7.6
EPSS
0.0028
EPSS Percentile
19.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Published
Sep 23, 2024
Tracked Since
Feb 18, 2026