VYPR
High severity7.8NVD Advisory· Published Mar 25, 2019· Updated Jun 17, 2026

CVE-2019-0204

CVE-2019-0204

Description

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.mesos:mesosMaven
< 1.4.31.4.3
org.apache.mesos:mesosMaven
>= 1.5.0, < 1.5.31.5.3
org.apache.mesos:mesosMaven
>= 1.6.0, < 1.6.21.6.2
org.apache.mesos:mesosMaven
>= 1.7.0, < 1.7.21.7.2

Affected products

5
  • Apache/Mesos2 versions
    cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:*range: >=1.4.0,<1.4.3
    • cpe:2.3:a:apache:mesos:1.8.0:dev:*:*:*:*:*:*
  • cpe:2.3:a:redhat:fuse:7.5.0:*:*:*:*:*:*:*
  • Apache/Apache Mesosv5
    Range: pre-1.4.x
  • ghsa-coords
    Range: < 1.4.3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.