Podman Elevated Container Privileges in github.com/containers/podman
Podman Elevated Container Privileges in github.com/containers/podman
02 / AFFECTED SOFTWARE
Affected packages
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Podman Elevated Container Privileges in github.com/containers/podman
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2018:2037
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10856
- https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24
- https://github.com/advisories/GHSA-wp7w-vx86-vj9h
- https://nvd.nist.gov/vuln/detail/CVE-2018-10856
- https://github.com/containers/podman