play-with-docker
play-with-docker copied to clipboard
Unauthorized Code Execution on the host [Play-with-Docker]
I have discovered a security vulnerability in the Play-with-Docker project, allowing me to execute code unlawfully on the project's host. I don't know where to report it for a safe fix.
hi there! you can contact me in marcosnils (at) gmail
I apologize for the earlier title, there was some confusion. Specifically, from within the containers, I can access the host machine and perform certain root-level actions. Would you like more details?
yes, please. Can you send me an email?