Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0234

Опубликовано: 04 янв. 2024
Источник: redhat
CVSS3: 7.8

Описание

A vulnerability was found in Podman Desktop. A misuse of RUN_AS_NODE set to true by default allows the usage of ELECTRON_RUN_AS_NODE, which might enable arbitrary code execution, and access to sensitive information for non-privileged processes.

Отчет

This issue only affectes the macOS version of the podman-desktop application. The podman-desktop is a graphical interface that runs on top of podman. Podman itself is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10podman-desktopNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2424600podman-desktop: Code injection Through Electron Fuses

7.8 High

CVSS3

7.8 High

CVSS3