Skip to main content

Improper Initialization

CVE-2019-14271

Severity High
Score 9.8/10

Summary

In Moby (Docker engine) 19.03.x prior to 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the "nsswitch" facility dynamically loads a library inside a chroot that contains the contents of the container.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-665 - Improper Initialization

The software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

Advisory Timeline

  • Published