CVE-2019-10152
Last modified
CVE-2019-10152 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libpod Project | Libpod | < 1.4.0 |
| Opensuse | Leap | 15.1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152Issue Tracking, Patch, Third Party Advisory
- https://github.com/containers/libpod/blob/master/RELEASE_NOTES.md#140Release Notes, Third Party Advisory
- https://github.com/containers/libpod/issues/3211Third Party Advisory
- https://github.com/containers/libpod/pull/3214Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152Issue Tracking, Patch, Third Party Advisory
- https://github.com/containers/libpod/blob/master/RELEASE_NOTES.md#140Release Notes, Third Party Advisory
- https://github.com/containers/libpod/issues/3211Third Party Advisory
- https://github.com/containers/libpod/pull/3214Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10152?
How severe is CVE-2019-10152?
How do I fix CVE-2019-10152?
Are you affected by CVE-2019-10152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
