First published: Tue Jul 30 2019(Updated: )
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libpod Project Libpod | <1.4.0 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10152 is a path traversal vulnerability in podman before version 1.4.0.
An attacker who has compromised an existing container can read/write arbitrary files on the host filesystem when an administrator tries to copy a file from the container.
podman before version 1.4.0, Libpod Project Libpod up to version 1.4.0, openSUSE Leap 15.1.
CVE-2019-10152 has a severity rating of 7.2 (high).
Update podman to version 1.4.0 or higher.