CVE-2022-36109 Affecting docker-bash-completion package, versions <20.10.23_ce-150000.175.1
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES151-DOCKERBASHCOMPLETION-3364328
- published 18 Mar 2023
- disclosed 17 Mar 2023
Introduced: 17 Mar 2023
CVE-2022-36109 Open this link in a new tabHow to fix?
Upgrade SLES:15.1
docker-bash-completion
to version 20.10.23_ce-150000.175.1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream docker-bash-completion
package and not the docker-bash-completion
package as distributed by SLES
.
See How to fix?
for SLES:15.1
relevant fixed versions and status.
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the "USER $USERNAME"
Dockerfile instruction. Instead by calling ENTRYPOINT ["su", "-", "user"]
the supplementary groups will be set up properly.
References
- https://www.suse.com/security/cve/CVE-2022-36109.html
- https://lists.suse.com/pipermail/sle-security-updates/2023-March/014082.html
- https://www.suse.com/support/update/announcement/2023/suse-su-20230795-1/
- https://bugzilla.suse.com/1205375
- https://bugzilla.suse.com/1206065
- https://www.suse.com/security/cve/CVE-2022-36109/
- https://www.suse.com/support/security/rating/
- https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4
- https://github.com/moby/moby/commit/de7af816e76a7fd3fbf06bffa6832959289fba32
- https://github.com/moby/moby/releases/tag/v20.10.18
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQQ4E3JBXVR3VK5FIZVJ3QS2TAOOXXTQ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O7JL2QA3RB732MLJ3RMUXB3IB7AA22YU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O7JL2QA3RB732MLJ3RMUXB3IB7AA22YU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQQ4E3JBXVR3VK5FIZVJ3QS2TAOOXXTQ/