VYPR

iSulad

by Openeuler

CVEs (5)

  • CVE-2021-33635CriOct 29, 2023
    risk 0.64cvss 9.8epss 0.01

    When malicious images are pulled by isula pull, attackers can execute arbitrary code.

  • CVE-2021-33638HigOct 29, 2023
    risk 0.55cvss 8.4epss 0.00

    When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.

  • CVE-2021-33637HigOct 29, 2023
    risk 0.55cvss 8.4epss 0.00

    When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.

  • CVE-2021-33636HigOct 29, 2023
    risk 0.55cvss 8.4epss 0.00

    When the isula load command is used to load malicious images, attackers can execute arbitrary code.

  • CVE-2021-33632HigMar 25, 2024
    risk 0.46cvss 7.0epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad…