A local malicious user can circumvent the Falco detection engine through 0.28.1 by running a program that alters arguments of system calls being executed. Issue is fixed in Falco versions >= 0.29.1.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/falcosecurity/falco/releases | third party advisory release notes |
https://github.com/falcosecurity/falco/pull/1675 | third party advisory patch |