Security Advisory

CVE-2018-11757

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-07-23 17:00:00
Last updated 2024-09-16 22:20:06
Assigner apache
State PUBLISHED

Description

In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an attacker to replace the user function inside the container if the user code is vulnerable to code exploitation.