Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2025-10832

около 1 года назад

Уязвимость сетевого стека для управления сетями контейнеров Netavark, связанная с восстановлением измененной резервной копии конфигурации, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 3.7
EPSS: Низкий
redos логотип

ROS-20250829-04

11 месяцев назад

Уязвимость netavark

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2025-8283

около 1 года назад

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2025-8283

около 1 года назад

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-8283

около 1 года назад

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-8283

около 1 года назад

A vulnerability was found in the netavark package, a network stack for ...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-rpcf-rmh6-42xr

около 1 года назад

Netavark Has Possible DNS Resolve Confusion

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-10832

Уязвимость сетевого стека для управления сетями контейнеров Netavark, связанная с восстановлением измененной резервной копии конфигурации, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 3.7
0%
Низкий
около 1 года назад
redos логотип
ROS-20250829-04

Уязвимость netavark

CVSS3: 3.7
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-8283

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

CVSS3: 3.7
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-8283

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

CVSS3: 3.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-8283

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

CVSS3: 3.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-8283

A vulnerability was found in the netavark package, a network stack for ...

CVSS3: 3.7
0%
Низкий
около 1 года назад
github логотип
GHSA-rpcf-rmh6-42xr

Netavark Has Possible DNS Resolve Confusion

CVSS3: 3.7
0%
Низкий
около 1 года назад

Уязвимостей на страницу