CyberRota Analysis
AI-GeneratedA vulnerability in kube-compare allows remote attackers to execute arbitrary code on an operator's workstation by improperly handling 'container://' reference paths, leading to the execution of untrusted container images. If the Docker daemon operates with elevated privileges, this could result in the execution of malicious code with root-level access, significantly increasing the risk to the system. Organizations using Docker and kube-compare should prioritize patching this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.