Vulnerabilities (CVE)

Filtered by vendor Anchore
Filtered by product Engine
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-11075 1 Anchore 1 Engine 2024-11-21 6.5 MEDIUM 7.7 HIGH
In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an authenticated user via a valid API request to anchore engine, or if an already added image that anchore is monitoring has its manifest altered to exploit the same flaw. A successful attack can be used to execute commands tha ...

Show More