The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/opencontainers/runc/libcontainer to version 1.3.6, 1.4.3, 1.5.0-rc.3 or higher.
github.com/opencontainers/runc/libcontainer is a package for a modern container runtime.
Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following in setupPtmx and setupDevSymlinks, which enable file deletion via calls to os.Remove and os.Symlink. An attacker who supplies a container image whose /dev is a symlink can redirect these operations outside the container, deleting host files named ptmx or creating a fixed set of named symlinks: core, fd, ptmx, stdin, stdout, stderr, in an arbitrary preexisting host directory. The practical impact is limited, since the symlink names and targets are fixed and unlikely to point to attacker-controlled data, and the ptmx files although guaranteed to exist, cannot be removed due to devpts constraints.
Note: This vulnerability is not exploitable under Docker.