+48
February 11, 2019, By Kacy Zurkus
A security issue that affects several open source container management systems, including Amazon Linux and Amazon Elastic Container Service, has been disclosed by
AWS.
The vulnerabilities (CVE-2019-5736) were
reportedly discovered by security researchers Adam Iwaniuk, Borys Poplawski and Aleksa Sarai and would allow an attacker with minimal user interaction to “overwrite the host runc binary and thus gain root-level code execution on the host.”
Also among the affected AWS containers are the service for Kubernetes (Amazon EKS), Fargate, IoT Greengrass, Batch, Elastic Beanstalk, Cloud 9, SageMaker, RoboMaker and Deep Learning AMI. In its security issue notice published 11 February, AWS said that no customer action is required for those containers not on the list.
Full Article.