Evaluate: Net Namespace
cdxy edited this page Dec 2, 2020
·
1 revision
Pages 49
Clone this wiki locally
Evaluate: Net Namespace
判断容器是否与宿主机共享Net Namespace, 如果docker以--net=host
启动且containerd-shim存在虚拟unix socket时,可通过CVE-2020-15257进行逃逸。
Check if container shares host's net namespace(e.g. docker run --net=host
). Containers with host net namespace can be escaped by CVE-2020-15257 when containerd-shim abstract unix socket found.
Usage
cdk evaluate