216.73.217.22

CVE-2025-53945

· Published 18/07/2025 16:15 · Modified 18/07/2025 16:15

Labels: CVE-2025-53945 2025-07-18CVE-2025-53945CWE-276[email protected]

Essential information

Published
18/07/2025 16:15
Modified
18/07/2025 16:15
Author
Creator
CVSS
7.0 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L

CVSS metrics

Description

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apko / apko cpe:2.3:a:apko:apko:*:*:*:*:*:*:*:*

References