CVE-2017-10940

CVE-2017-10940

Vendor Joyent
Product Joyent Smart Data Center
Weakness CWE-22 · Path traversal
Published October 31, 2017
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to agentsshar@1.0.0-release-20160901-20160901T051624Z-g3fd5adf (e469cf49-4de3-4658-8419-ab42837916ad). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the docker API. The process does not properly validate user-supplied data which can allow for the upload of arbitrary files. An attacker can leverage this vulnerability to execute arbitrary code under the context of root. Was ZDI-CAN-3853.

Key dates

02Disclosure timeline

October 31, 2017 CVE published
August 5, 2024 Record updated