CVE-2019-10152 – github.com/containers/podman
Package
Manager: go
Name: github.com/containers/podman
Vulnerable Version: >=0 <1.4.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
EPSS: 0.00357 pctl0.57246
Details
Podman Path Traversal Vulnerability leads to arbitrary file read/write A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Metadata
Created: 2022-05-24T16:51:48Z
Modified: 2023-08-25T21:29:12Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rh5f-2w6r-q7vj/GHSA-rh5f-2w6r-q7vj.json
CWE IDs: ["CWE-22", "CWE-59"]
Alternative ID: GHSA-rh5f-2w6r-q7vj
Finding: F063
Auto approve: 1