{"containers":{"cna":{"title":"Azure Service Fabric Container Elevation of Privilege Vulnerability","datePublic":"2022-06-14T07:00:00.000Z","cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:service_fabric:*:*:*:*:*:*:*:*","versionStartIncluding":"N/A"}]}]}],"affected":[{"vendor":"Microsoft","product":"Service Fabric","platforms":["Unknown"],"versions":[{"version":"N/A","status":"affected"}]}],"descriptions":[{"value":"Executive Summary\nAn Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers.  Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container.  All Service Fabric and Docker versions are impacted.","lang":"en-US"}],"problemTypes":[{"descriptions":[{"description":"Remote Code Execution","lang":"en-US","type":"Impact"}]}],"providerMetadata":{"orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft","dateUpdated":"2025-01-02T19:02:52.975Z"},"references":[{"name":"Azure Service Fabric Container Elevation of Privilege Vulnerability","tags":["vendor-advisory"],"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","baseSeverity":"MEDIUM","baseScore":6.7,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C"}}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T06:40:47.578Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30137"}]}]},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2022-30137","datePublished":"2022-06-15T21:51:24.000Z","dateReserved":"2022-05-03T00:00:00.000Z","dateUpdated":"2025-01-02T19:02:52.975Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}