Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
cifs.upcall makes an upcall to the wrong namespace in containerized environments
Vulnerability Description
A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
对错误会话暴露数据元素
Vulnerability Title
cifs-utils 安全漏洞
Vulnerability Description
cifs-utils是Pavel Shilovsky个人开发者的一个工具包。提供用于管理 CIFS 网络文件系统安装的实用程序。 cifs-utils存在安全漏洞,该漏洞源于cifs.upcall程序在容器环境中错误地调用命名空间,可能导致主机Kerberos凭据缓存中的敏感数据泄露。
CVSS Information
N/A
Vulnerability Type
N/A