CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
code execution
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2020-8945
Severity
HIGH
CVSS
7.5
EPSS
5.07%
Docker
Original NVD Description
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.