CVE-2020-11075
CVE-2020-11075 — Shell Escape in Anchore Engine
In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an authenticated user via a valid API request to anchore engine, or if an already added image that anchore is monitoring has its manifest altered to exploit the same flaw. A successful attack can be used to execute commands that run in the analyzer environment, with the same permissions as the user that anchore engine is run as - including access to the credentials that Engine uses to access its own database which have read-write ability, as well as access to the running engien analyzer service environment. By default Anchore Engine is released and deployed as a container where the user is non-root, but if users run…
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
2%
chance of exploitation in 30 days
CVSS base
7.7
HIGH
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 7.7 | CVSS 3.1 | HIGH | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-114
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1505.005Server Software Component: Terminal Services DLL
- T1574.006Hijack Execution Flow: Dynamic Linker Hijacking
- T1574.013Hijack Execution Flow: KernelCallbackTable
References
4 on the record
- github.com/anchore/anchore-engine/security/advisories/GHSA-w4rm-w22x-h7m5
x_refsource_CONFIRM
- github.com/anchore/anchore-engine/issues/430
x_refsource_MISC
- github.com/anchore/anchore-engine/pull/431
x_refsource_MISC
- github.com/anchore/anchore-engine/commit/e41786901f097fd32104447a45864073105d37db
x_refsource_MISC
Elsewhere on this site
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.