Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m68q-4hqr-mc6f

Опубликовано: 16 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Podman Creates Temporary File with Insecure Permissions

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

Пакеты

Наименование

github.com/containers/podman/v5

go
Затронутые версииВерсия исправления

<= 5.5.0

Отсутствует

EPSS

Процентиль: 21%
0.00069
Низкий

7.4 High

CVSS3

Дефекты

CWE-378

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

CVSS3: 7.4
redhat
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

CVSS3: 7.4
nvd
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

msrc
17 дней назад

Podman: build context bind mount

CVSS3: 7.4
debian
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written ...

EPSS

Процентиль: 21%
0.00069
Низкий

7.4 High

CVSS3

Дефекты

CWE-378