PT-2021-13830 · Podman+5 · Podman+5

Riccardo Schirone

·

Published

2020-03-19

·

Updated

2024-08-21

·

CVE-2021-20188

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: podman versions prior to 1.7.0
Description: A flaw was found in podman where file permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root user inside the container. Although it does not allow direct escape from the container, the fact that it is a privileged container means many security features are disabled. The highest threat from this issue is to data confidentiality and integrity as well as system availability.
Recommendations: For podman versions prior to 1.7.0, update to version 1.7.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of privileged containers to minimize the risk of exploitation. Additionally, ensure that access to sensitive files within the container is tightly controlled and monitored.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALSA-2020:3053
ALSA-2021:0705
ALSA-2021:0706
ALT-PU-2020-1528
ALT-PU-2020-1645
CESA-2020_3053
CESA-2021_0705
CESA-2021_0706
CVE-2021-20188
GHSA-9H63-7QF6-MV6R
GO-2022-0641
OESA-2021-1123
RHSA-2020:3053
RHSA-2020_3053
RHSA-2021:0681
RHSA-2021:0705
RHSA-2021:0706
RHSA-2021:0710
RHSA-2021_0705
RHSA-2021_0706
RLSA-2020:3053
RLSA-2021:0705
RLSA-2021:0706

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Podman