blob: e932f532407d86e039dea669f2aae60dc7a8a0d8 [file] [log] [blame]
id: GO-2024-2913
modules:
- module: github.com/docker/docker
versions:
- fixed: 20.10.9+incompatible
vulnerable_at: 20.10.8+incompatible
packages:
- package: github.com/docker/docker/pkg/chrootarchive
symbols:
- untarHandler
skip_fix: fix error due to incompatible versions
- module: github.com/moby/moby
versions:
- fixed: 20.10.9+incompatible
vulnerable_at: 20.10.8+incompatible
packages:
- package: github.com/moby/moby/pkg/chrootarchive
symbols:
- untarHandler
skip_fix: fix error due to incompatible versions
summary: Unexpected chmod of host files via 'docker cp' in Moby Docker Engine in github.com/docker/docker
cves:
- CVE-2021-41089
ghsas:
- GHSA-v994-f8vw-g7j4
references:
- advisory: https://github.com/moby/moby/security/advisories/GHSA-v994-f8vw-g7j4
- fix: https://github.com/moby/moby/commit/bce32e5c93be4caf1a592582155b9cb837fc129a
source:
id: GHSA-v994-f8vw-g7j4
created: 2024-07-01T14:35:32.733244-04:00
review_status: REVIEWED