CVE-2019-10152: Path Traversal
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10152?
CVE-2019-10152 is a path traversal vulnerability in podman before version 1.4.0.
How does CVE-2019-10152 affect the host filesystem?
An attacker who has compromised an existing container can read/write arbitrary files on the host filesystem when an administrator tries to copy a file from the container.
Which software versions are affected by CVE-2019-10152?
podman before version 1.4.0, Libpod Project Libpod up to version 1.4.0, openSUSE Leap 15.1.
What is the severity of CVE-2019-10152?
CVE-2019-10152 has a severity rating of 7.2 (high).
How can I fix CVE-2019-10152?
Update podman to version 1.4.0 or higher.