Get a Pentest and security assessment of your IT network.

Cyber Security

Unpatched Flaw Affects All Docker Versions, Exploits Ready

All versions of Docker are currently vulnerable to a race condition that could give an attacker both read and write access to any file on the host system. At its core, the vulnerability stems from the FollowSymlinkInScope function. The vulnerability is similar to CVE-2018-15664 and it offers a window of opportunity for hackers to modify resource paths after resolution but before the assigned program starts operating on the resource. A patch has been submitted upstream and is still under review. Mitigating mitigation options and exploit scripts offer potential mitigation solutions.

Source: https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security