Описание
A vulnerability was found in Podman Desktop. A misuse of RUN_AS_NODE set to true by default allows the usage of ELECTRON_RUN_AS_NODE, which might enable arbitrary code execution, and access to sensitive information for non-privileged processes.
Отчет
This issue only affectes the macOS version of the podman-desktop application. The podman-desktop is a graphical interface that runs on top of podman. Podman itself is not affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | podman-desktop | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2424600podman-desktop: Code injection Through Electron Fuses
7.8 High
CVSS3
7.8 High
CVSS3