CVE-2019-16884: Incorrect Authorization
(updated )
runc through allows AppArmor restriction bypass because libcontainer/rootfs_linux.go
incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc
directory.
References
Detect and mitigate CVE-2019-16884 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →