CVE-2021-21284 - CVE House
Back to Database
Status published Medium CVE-2021-21284

privilege escalation in Moby

Vulnerability Description

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/<remapping>" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-21284

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

moby
Vulnerable Versions:
< 19.03.15, >= 20.0.0, < 20.10.3

Timeline

Official Publish: February 2nd, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Weaknesses (CWE)