CVE-2022-41717:

Overview

Severity
Medium (CVSS 5.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploit Status
Not Exploited
Patch Tuesday
2024-Dec
Released
2022-12-12
Last Updated
2024-12-02
EPSS Score
5.62% (percentile: 92.2%)

Detection & Weaponization (1 sources)

Maturity: Exploit

  • GitHub PoC: 1 repositories

Affected Products (6)

Mariner

  • CBL Mariner 1.0 x64
  • CBL Mariner 1.0 ARM
  • CBL Mariner 2.0 x64
  • CBL Mariner 2.0 ARM
  • Azure Linux 3.0 x64
  • Azure Linux 3.0 ARM

Revision History

  • 2022-12-12: Information published.
  • 2024-01-23: Added sriov-network-device-plugin to CBL-Mariner 2.0
  • 2024-02-11: Added nmi to CBL-Mariner 2.0
  • 2024-04-10: Added cri-o to CBL-Mariner 2.0
  • 2024-06-30: Information published.
  • 2024-09-05: Information published.
  • 2024-09-06: Information published.
  • 2024-09-07: Information published.
  • 2024-09-10: Information published.
  • 2024-10-04: Information published.
  • 2024-10-15: Added prometheus to CBL-Mariner 2.0 Added containerized-data-importer to CBL-Mariner 2.0 Added azcopy to CBL-Mariner 2.0 Added cri-o to CBL-Mariner 2.0 Added moby-cli to CBL-Mariner 2.0 Added nmi to CBL-Mariner 2.0 Added sriov-network-device-plugin to CBL-Mariner 2.0 Added golang to CBL-Mariner 2.0 Added moby-engine to Azure Linux 3.0 Added sriov-network-device-plugin to Azure Linux 3.0 Added prometheus to Azure Linux 3.0 Added golang to CBL-Mariner 1.0
  • 2024-12-02: Added containerized-data-importer to CBL-Mariner 2.0 Added prometheus to CBL-Mariner 2.0 Added azcopy to CBL-Mariner 2.0 Added cri-o to CBL-Mariner 2.0 Added moby-cli to CBL-Mariner 2.0 Added nmi to CBL-Mariner 2.0 Added sriov-network-device-plugin to CBL-Mariner 2.0 Added golang to CBL-Mariner 2.0 Added moby-engine to Azure Linux 3.0 Added sriov-network-device-plugin to Azure Linux 3.0 Added prometheus to Azure Linux 3.0 Added golang to CBL-Mariner 1.0