Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp7w-vx86-vj9h

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Podman Elevated Container Privileges

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.

Пакеты

Наименование

github.com/containers/podman

go
Затронутые версииВерсия исправления

< 0.6.1

0.6.1

EPSS

Процентиль: 44%
0.00216
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.3
redhat
больше 7 лет назад

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.

CVSS3: 5.3
nvd
больше 7 лет назад

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.

CVSS3: 5.3
debian
больше 7 лет назад

It has been discovered that podman before version 0.6.1 does not drop ...

EPSS

Процентиль: 44%
0.00216
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-732