Описание
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
A flaw was found in podman. Rootless containers receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts) which impact containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. The highest threat from this vulnerability is to data integrity.
Отчет
This issue does not affect Podman prior to version 1.8.0. Podman shipped in the following products are therefore not affected:
- Red Hat Enterprise Linux 7 Extras
- Red Hat Enterprise Linux 8 Container Tools stream 1.0
- Red Hat Enterprise Linux 8 Container Tools stream 2.0
- OpenShift Container Platform 3.11
- OpenShift Container Platform 4.1 to 4.5
Меры по смягчению последствий
Configure containerized applications to require authentication for connections from all sources, including localhost.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | podman | Not affected | ||
Red Hat Enterprise Linux 8 | container-tools:1.0/podman | Not affected | ||
Red Hat Enterprise Linux 8 | container-tools:2.0/podman | Not affected | ||
Red Hat OpenShift Container Platform 3.11 | podman | Not affected | ||
Red Hat OpenShift Container Platform 4 | podman | Will not fix | ||
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2021:1796 | 18.05.2021 |
Red Hat Enterprise Linux 9 | podman | Fixed | RHSA-2022:7954 | 15.11.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
Rootless containers run with Podman, receive all traffic with a source ...
EPSS
5.9 Medium
CVSS3