FlawAtlas
Search the atlas
CVE-2018-10856 High

Podman Elevated Container Privileges in github.com/containers/podman

Podman Elevated Container Privileges in github.com/containers/podman

Exploit probability 0.9%
Published August 20, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

Go github.com/containers/podman
Go github.com/containers/podman/v2
Go github.com/containers/podman/v3
Go github.com/containers/podman/v4
Go github.com/containers/podman

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2018-10856

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.

View original source
Open Source Vulnerabilities GO-2023-1962

Podman Elevated Container Privileges in github.com/containers/podman

View original source
Open Source Vulnerabilities GHSA-wp7w-vx86-vj9h

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.

View original source

05 / REFERENCES

Further evidence