CVE-2021-20199: Infoleak
A flaw was found in podman. Rootless containers receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts) which impact containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. The highest threat from this vulnerability is to data integrity.
Other sources
Rootless containers run with Podman, in versions from 1.8.0 onward, receive all traffic with a sourceIP of 127.0.0.1 (including from remote hosts). This can impact containerized applications that trust localhost (127.0.01) connections by default and do not require authentication.
Upstream issue:
https://github.com/containers/podman/issues/5138
— Red Hat
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman versions from 1.8.0 to 3.0.0.
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20199.
What is the severity of CVE-2021-20199?
The severity of CVE-2021-20199 is medium with a CVSS score of 5.9.
How does CVE-2021-20199 impact rootless containers running with Podman?
CVE-2021-20199 impacts rootless containers running with Podman by causing them to receive all traffic with a source IP address of 127.0.0.1, including from remote hosts.
Which containerized applications are affected by CVE-2021-20199?
Containerized applications that trust localhost (127.0.0.1) connections by default and do not require authentication are affected by CVE-2021-20199.
How can I fix CVE-2021-20199?
To fix CVE-2021-20199, you should update your Podman package to version 2.4.2-3.el9 or later.