Podatność CVE-2021-20208


Publikacja: 2021-04-19   Modyfikacja: 2021-04-20

Opis:
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.

Typ:

CWE-266

(Incorrect Privilege Assignment)

 Referencje:
https://bugzilla.redhat.com/show_bug.cgi?id=1921116
https://bugzilla.samba.org/show_bug.cgi?id=14651

Copyright 2024, cxsecurity.com

 

Back to Top