Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14370

Опубликовано: 22 сент. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

An information disclosure flaw was found in containers/podman. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container leak into subsequent containers. This flaw allows an attacker who controls the subsequent containers to gain access to sensitive information stored in such variables. The highest threat from this vulnerability is to confidentiality.

Отчет

Whilst OpenShift Container Platform (OCP) does include podman, the Varlink API is not enabled by default. However, as it is trivial to activate this feature, OCP has been marked as affected. OCP 3.11 has previously packaged podman, but instead now relies on the version from rhel-extra.The older version previously packaged is not vulnerable to this CVE and hence has been marked not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8container-tools:1.0/podmanNot affected
Red Hat Enterprise Linux 8container-tools:2.0/podmanAffected
Red Hat OpenShift Container Platform 3.11podmanNot affected
Red Hat Enterprise Linux 7 ExtraspodmanFixedRHSA-2020:505610.11.2020
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2021:053116.02.2021
Red Hat OpenShift Container Platform 4.6podmanFixedRHSA-2020:429727.10.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=1874268podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API

EPSS

Процентиль: 31%
0.00115
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
nvd
больше 4 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
debian
больше 4 лет назад

An information disclosure vulnerability was found in containers/podman ...

suse-cvrf
больше 4 лет назад

Security update for podman

suse-cvrf
больше 4 лет назад

Security update for podman

EPSS

Процентиль: 31%
0.00115
Низкий

5.3 Medium

CVSS3