docker-socket-proxy не может правильно контролировать конечные точки чтения в пространстве имен Docker API /containers, когда установлена переменная среды CONTAINERS. Злоумышленники могут использовать запросы GET к /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs и /containers/{id}/top для чтения произвольных файлов и загрузки целых файловых систем контейнеров в виде tar-архивов.
Показать оригинальное описание (EN)
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.
Характеристики атаки
Последствия
Строка CVSS v4.0