CVE-2020-8945

HIGHCVSS 7.5/10EPSS 5.07%

Last modified

CVE-2020-8945 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.. EPSS estimates a 5.07% chance of exploitation in the next 30 days.

Description

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
5.07%

91.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Gpgme ProjectGpgme< 0.1.1
RedhatOpenshift Container Platform3.11
RedhatOpenshift Container Platform4.1
RedhatOpenshift Container Platform4.2
RedhatOpenshift Container Platform4.3
RedhatOpenshift Container Platform4.4
RedhatOpenshift Container Platform4.5
RedhatOpenshift Container Platform For Ibm Z4.1
RedhatOpenshift Container Platform For Ibm Z4.2
RedhatOpenshift Container Platform For Linuxone4.1
RedhatOpenshift Container Platform For Linuxone4.2
FedoraprojectFedora30
FedoraprojectFedora31
FedoraprojectFedora32
RedhatEnterprise Linux For Ibm Z Systems7.0
RedhatEnterprise Linux For Power Little Endian7.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Workstation7.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8945?
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
How severe is CVE-2020-8945?
CVE-2020-8945 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 5.07% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8945?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8945?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST