[CVE-2020-28914] Big Bugs:Bitbucket Pipelines 中 Kata Containers 构建容器逃逸
bugcrowd.com | 漏洞 | CVE-2020-28914 | #container-security | #container-escape | #cve-2020-28914 | #kata-containers | #bitbucket-pipelines | #ci-cd-security | #atlassian
摘要
研究者 Alex Chapman 在 Atlassian 于 Bugcrowd 发起的项目中发现 Kata Containers 漏洞(CVE-2020-28914):Kata VM 内进程可写入本应只读的卷挂载,恶意构建任务借此能以 root 身份篡改 Bitbucket Pipelines 宿主机文件,波及多租户环境中的其他客户构建。
- 发布时间
- 收录时间
Skip to content