
🚨 CVE-2017-20198: DC/OS Marathon UI < 1.9.0 Unauth... Unauthenticated root via Docker mount abuse - deploy malicious container, mount host `/`, write to `/etc/cron.d/` for p... https://zerodaysignal.com/vulnerability/CVE-2017-20198 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces CVE‑2017‑20198, detailing how an attacker can achieve root by mounting the host filesystem inside a Docker container and writing to /etc/cron.d/, and links to a vulnerability report for more information.
