bottlerocket-os Hotdog privilege escalation | CVE-2022-0071
NAME
bottlerocket-os Hotdog privilege escalation
- Platforms Affected:
bottlerocket-os Hotdog 1.0.1 - Risk Level:
8.8 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
bottlerocket-os Hotdog could allow a local authenticated attacker to gain elevated privileges on the system, caused by not mimic the resource limits device restrictions, or syscall filters of the target JVM process. By using a specially-crafted container, an authenticated attacker could exploit this vulnerability to gain elevated privleges to exhaust the resources of the host, modify devices, or make syscalls that would otherwise be blocked..
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Changed
- Access Vector: Local
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of Hotdog (1.0.2 or later), available from the Hotdog GIT Repository. See References.
- Reference Link:
https://github.com/bottlerocket-os/hotdog/security/advisories/GHSA-jr96-7frv-3mpj - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0071
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.