Apptainer has incorrect path matching for 'limit container paths' directive
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
별도 긴급 패치 불필요 — 정기 시스템 업그레이드 주기에 맞춰 조치
CVSS 벡터 · 메트릭
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L상세 설명
Impact
The limit container paths directive in apptainer.conf is intended to allow a system administrator limit the paths from which containers can be run, under setuid mode. Due to incorrect matching of a path string, sibling directories with similar names may incorrectly be allowed.
For example, the configuration:
1limit container paths = /data/safeWill also allow containers in /data/safe-but-unsafe to be run.
Patches
The issue is patched in apptainer version 1.5.1.
Workarounds
If developers do not use setuid mode or do not use the limit container paths functionality, then this issue does not affect their installation. Note that, as documented [1], if user namespaces are allowed for unrestricted use then this functionality does not stop users from running any container of their choice.
If developers do use the limit container paths functionality they are advised to update.
Credit
This vulnerability was discovered and disclosed to the Apptainer project by Dave Trudgian of Sylabs.
Resources
[1] https://apptainer.org/docs/admin/latest/configfiles.html#limiting-container-execution
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.