Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-38496
Description:Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rather limited for users but an attacker could possibly craft a starter config to delete any directory on the host filesystems. A security fix has been included in Apptainer 1.2.1. There is no known workaround outside of upgrading to Apptainer 1.2.1.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-38496
https://github.com/apptainer/apptainer/pull/1523
https://github.com/apptainer/apptainer/pull/1523
https://github.com/apptainer/apptainer/pull/1578
https://github.com/apptainer/apptainer/pull/1578
https://github.com/apptainer/apptainer/security/advisories/GHSA-mmx5-32m4-wxvx
https://github.com/apptainer/apptainer/security/advisories/GHSA-mmx5-32m4-wxvx




© 1998-2025 E-Soft Inc. All rights reserved.