Snapcraft's vulnerability profile centers on snapd, the daemon and package-management system underlying the snap application ecosystem on Linux. The observed weakness class involves improper handling of exceptional conditions in the core snap runtime, reflecting the complexity of sandboxing and permission-management logic in a widely deployed package delivery system. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snapcraft over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14178HIGH In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass syst | Feb 2, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snapcraft.
Media articles that mention a CVE ID that affects a product developed by Snapcraft — matched by CVE ID, not by vendor name.