Podman Project

Podman

14 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Published 02.08.2024 21:16:30
  • Last modified 27.12.2024 16:15:24

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious ...

  • EPSS 0.12%
  • Published 27.03.2023 21:15:10
  • Last modified 24.02.2025 18:15:16

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

  • EPSS 0.13%
  • Published 08.12.2022 16:15:14
  • Last modified 22.04.2025 21:15:44

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

  • EPSS 0.03%
  • Published 08.12.2022 16:15:14
  • Last modified 22.04.2025 21:15:44

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

Exploit
  • EPSS 0.04%
  • Published 13.09.2022 14:15:08
  • Last modified 05.06.2025 19:15:23

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups ar...

  • EPSS 0.49%
  • Published 01.09.2022 21:15:09
  • Last modified 21.11.2024 07:01:36

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be...

  • EPSS 0.17%
  • Published 01.09.2022 21:15:09
  • Last modified 21.11.2024 07:01:36

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly a...

Exploit
  • EPSS 0.8%
  • Published 09.06.2022 17:15:08
  • Last modified 21.11.2024 04:39:52

A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The ex...

Exploit
  • EPSS 34.75%
  • Published 29.04.2022 16:15:08
  • Last modified 21.11.2024 06:40:17

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' co...

  • EPSS 0.63%
  • Published 04.04.2022 20:15:10
  • Last modified 21.11.2024 06:56:05

A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabiliti...