The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/07/26/9 | mailing list vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1360634 | issue tracking third party advisory |
http://www.openwall.com/lists/oss-security/2016/10/13/7 | third party advisory mailing list |
https://github.com/projectatomic/oci-register-machine/pull/22 | patch |
http://www.securityfocus.com/bid/92143 | vdb entry third party advisory |