Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-0778

Опубликовано: 27 мар. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.8

Описание

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 32%
0.00125
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
redhat
почти 3 года назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
nvd
почти 3 года назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
msrc
5 месяцев назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
debian
почти 3 года назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This is ...

suse-cvrf
почти 3 года назад

Security update for podman

EPSS

Процентиль: 32%
0.00125
Низкий

6.8 Medium

CVSS3