CVE-2018-11757
CVE-2018-11757
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 6.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Jul 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an attacker to replace the user function inside the container if the user code is vulnerable to code exploitation.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →