Comment on Vulnerabilities on Dockerhub

<- View Parent
_Nemo_@lemmy.ml ⁨2⁩ ⁨days⁩ ago

Thanks for your detailed reply!

To make that happen, the attacker must […] already have access to the server to upload and process the file, which means that security has already failed.

Do I correctly assume that by axis you mean shell or even root level access? If not, any of my regular users (turned rogue…) could upload a poisoned raw file which nextcloud would process to, for instance, generate a thumbnail.

original
Sort:hotnewtop