Back

HIGH

mesos: docker image code execution

Published Mar 25, 2019

Description

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 25, 2019
Updated Aug 4, 2024
Reserved Nov 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 23, 2019
GHSA-32W9-2QPC-5F9V