Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwqv-rqgf-8qh8

Опубликовано: 27 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Podman Time-of-check Time-of-use (TOCTOU) Race Condition

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Пакеты

Наименование

github.com/containers/podman/v4

go
Затронутые версииВерсия исправления

< 4.4.2

4.4.2

EPSS

Процентиль: 31%
0.00115
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
redhat
больше 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
nvd
около 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
debian
около 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This is ...

suse-cvrf
около 2 лет назад

Security update for podman

EPSS

Процентиль: 31%
0.00115
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-367