HIGH 7.8 Go

Privilege Elevation in runc

GHSA-q3j5-32m5-58c2 · CVE-2016-3697 · GO-2021-0070

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

Ready to move

Start Securing

Free, no credit card | First findings in minutes