A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2022-1483 | A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution. | 
  Github GHSA | 
                GHSA-mq47-6wwv-v79w | Path traversal in claircore | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:09:08.890Z
Reserved: 2021-09-03T00:00:00
Link: CVE-2021-3762
No data.
Status : Modified
Published: 2022-03-03T22:15:08.467
Modified: 2024-11-21T06:22:21.860
Link: CVE-2021-3762
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA