CVE-2021-29136: Improper Input Validation
The Open Container Initiative’s umoci allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when umoci unpack
or umoci raw unpack
is used.
References
Detect and mitigate CVE-2021-29136 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →