CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libpod Project Redhat3Enterprise Linux LibpodOpenshift Container PlatformNov 21, 2024 Feb 11, 2020 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container bas...Show more |
5Buildah Project Libpod ProjectOpensuse+2 more6Buildah Enterprise LinuxLeap+3 moreNov 21, 2024 Nov 25, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more |
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could cr...Show more |
2Libpod Project Opensuse2Leap LibpodNov 21, 2024 Jul 30, 2019 N/A· v4 7.2 HIGH· v3 2.6 LOW· v2 A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the h...Show more |
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container. |