Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-41091

23
FAUCET Score

CVE-2021-41091 is a medium-severity vulnerability in Moby (Docker Engine) affecting Fedora and Moby products. It allows unprivileged Linux users on the host to traverse container data directories, discover and execute programs with extended permissions (like setuid), and potentially read or modify container files due to UID collisions. The vulnerability has a CVSS score of 6.3, indicating a local attack vector with low complexity, leading to potential low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Users are advised to update to Moby 20.10.9 and restart containers, or implement host access and volume restrictions if unable to upgrade.

Impacted Technologies

VendorProductVersion(s)CPE
< 20.10.9CPE matchmatch criteria
cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.0
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.69%
Probability of exploitation in next 30 days
EPSS Percentile
84.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0269 is in the 99th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/docker/dockerFixed in: 20.10.9
gopatch availablevia ghsa
Product: github.com/moby/mobyFixed in: 20.10.9
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm-assisted-service-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-compliance-openscap-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-compliance-operator-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-file-integrity-operator-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform Assisted Installer 1Fixed in: rhai-tech-preview/assisted-installer-reporter-rhel8
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-controller-rhel9
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/agent-service-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4-wincw/windows-machine-config-rhel8-operator

Vendor Advisories (2)

goGHSA-3fwx-pjgw-3558medium

Moby (Docker Engine) Insufficiently restricted permissions on data directory

Jan 31, 2024
redhatCVE-2021-41091Moderate

moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal

Oct 4, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-222547.pdf
github.com / moby/moby/commit/f0ab919f518c47240ea0e72d0999576bb8008e64
PatchThird Party Advisory
github.com / moby/moby/security/advisories/GHSA-3fwx-pjgw-3558
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/B5Q6G6I4W5COQE25QMC7FJY3I3PAYFBB
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZNFADTCHHYWVM6W4NJ6CB4FNFM2VMBIB