Skip to content

hotdog CVE-2021-3101

High
cbgbt published GHSA-7cq8-2wg2-g3wm Dec 24, 2021

Package

hotdog (bottlerocket)

Affected versions

< 1.5.1

Patched versions

1.5.1

Description

Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.

Severity

High

CVE ID

CVE-2021-3101

Weaknesses

No CWEs