Date: Wed, 29 Sep 2021 20:20:22 +0200
From: Przemyslaw Roguski <>
Subject: CVE-2021-3762 quay/claircore: directory traversal when scanning
 crafted container image


A directory traversal vulnerability was found in the ClairCore engine of
An attacker can exploit this by supplying a crafted container image which,
when scanned by Clair, allows for arbitrary file write on the filesystem,
potentially allowing for remote code execution.

Red Hat has assigned CVE-2021-3762 to this vulnerability.
These issues have been rated Critical, with a CVSS:

### Affected Versions
ClairCore 0.4.6 release and higher (Clair v4.1.4 and higher)
ClairCore 0.5.3 release and higher (Clair v4.2.1 and higher)

### Fixed Versions
ClairCore v0.4.8 (shipped in Clair v4.1.6)
ClairCore v0.5.5 (shipped in Clair v4.2.3)

### Fixes

## Acknowledgements
Yanir Tsarimi
(Orca Security)

Best regards,
Przemyslaw Roguski

Przemyslaw Roguski / Red Hat Product Security

