Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25067

Опубликовано: 09 июн. 2019
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-143949 was assigned to this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7podmanFix deferred
Red Hat Enterprise Linux 8container-tools:2.0/podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:3.0/podmanNot affected
Red Hat Enterprise Linux 8container-tools:4.0/podmanNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 9podmanNot affected
Red Hat OpenShift Container Platform 3.11podmanNot affected
Red Hat OpenShift Container Platform 4podmanAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2097406podman: Privilege escalation in API component

EPSS

Процентиль: 84%
0.02552
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 4 лет назад

A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-143949 was assigned to this vulnerability.

CVSS3: 6.3
nvd
около 4 лет назад

A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-143949 was assigned to this vulnerability.

CVSS3: 6.3
debian
около 4 лет назад

A vulnerability, which was classified as critical, was found in Podman ...

CVSS3: 8.8
github
около 4 лет назад

A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 84%
0.02552
Низкий

8.1 High

CVSS3