彙總 projectatomic 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
常見弱點模式包括 輸入驗證問題與路徑處理缺陷,在 生產負載與軟體部署 使用場景中可能帶來 異常行為與檔案覆寫 等風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2020-5291 | Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to | [email protected] | 7.2 | 0.91% | 2020-03-31 | 2024-11-21 |
| CVE-2019-12439 | bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code. | [email protected] | 7.4 | 0.49% | 2019-05-29 | 2024-11-21 |
| CVE-2017-5226 | When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox. | [email protected] | 10.0 | 3.17% | 2017-03-29 | 2026-05-13 |
| CVE-2016-6349 | The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command. | [email protected] | 3.3 | 0.40% | 2017-03-29 | 2026-05-13 |