PT-2019-11599 · Red Hat+1 · Podman+1
Sfowl
·
Published
2019-07-30
·
Updated
2024-08-20
·
CVE-2019-10152
CVSS v3.1
7.5
High
| Vector | AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
podman versions prior to 1.4.0
Description:
A path traversal issue has been found in the way podman handles symlinks inside containers. This could allow an attacker who has already compromised a container to read or write arbitrary files on the host filesystem when an administrator attempts to copy files to or from the container.
Recommendations:
For versions prior to 1.4.0, update to version 1.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files on the host filesystem and limiting the use of symlinks inside containers until the update can be applied.
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Podman