VYPR
Critical severity9.8NVD Advisory· Published Mar 3, 2022· Updated Jun 17, 2026

CVE-2021-3762

CVE-2021-3762

Description

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/quay/claircoreGo
< 0.4.80.4.8
github.com/quay/claircoreGo
>= 1.0.0, < 1.1.01.1.0
github.com/quay/claircoreGo
>= 0.5.0, < 0.5.50.5.5

Affected products

2

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.