Description
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5384 | A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0. |
Github GHSA |
GHSA-vmhj-p9hw-vgrf | Podman has Files or Directories Accessible to External Parties |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T06:46:30.890Z
Reserved: 2019-11-27T00:00:00.000Z
Link: CVE-2020-1726
No data.
Status : Modified
Published: 2020-02-11T20:15:12.070
Modified: 2024-11-21T05:11:15.030
Link: CVE-2020-1726
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA