Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3wv-qmjj-45r6

Опубликовано: 24 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Information disclosure in podman

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

Пакеты

Наименование

github.com/containers/podman/v2

go
Затронутые версииВерсия исправления

< 2.0.5

2.0.5

EPSS

Процентиль: 31%
0.00115
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-212

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
redhat
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
nvd
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
debian
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman ...

suse-cvrf
больше 4 лет назад

Security update for podman

EPSS

Процентиль: 31%
0.00115
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-212