VYPR

DC/OS

by DC/OS

CVEs (1)

  • CVE-2017-20198CriJul 23, 2025
    risk 0.69cvss epss 0.73

    The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount configurations, attackers can deploy a container that mounts the host's root filesystem (/) with read/write privileges. When using a…