VDB

CVE-2019-0204

CVE-2019-0204 PUBLISHED

Reported by apache · Published March 25, 2019

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

Affected Products

VendorProductVersions
ApacheApache Mesospre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2
Mavenorg.apache.mesos:mesos1.4.0, 1.4.0
ApacheApache Mesos1.6.0 to 1.6.1, *, *

Timeline

  • Mar 25, 2019 CVE Published
  • Nov 15, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›