ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-24264”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-24264
Published
2021-03-16
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be leveraged to break out of the container leading to complete Docker host machine takeover.