Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
High
CVE-2021-3493
Disclosure Date: April 15, 2021 (last updated February 22, 2025)
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
1
Attacker Value
Unknown
CVE-2024-46975
Disclosure Date: February 22, 2025 (last updated February 23, 2025)
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.
0
Attacker Value
Unknown
CVE-2020-1719
Disclosure Date: June 07, 2021 (last updated February 22, 2025)
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected.
0
Attacker Value
Unknown
CVE-2020-7020
Disclosure Date: October 22, 2020 (last updated February 22, 2025)
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
0
Attacker Value
Unknown
CVE-2020-7019
Disclosure Date: August 18, 2020 (last updated February 22, 2025)
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fields that should be hidden. This could result in an attacker gaining additional permissions against a restricted index.
0
Attacker Value
Unknown
CVE-2019-14819
Disclosure Date: January 07, 2020 (last updated February 21, 2025)
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
0