FlawAtlas
Search the atlas
CVE-2020-14370 Moderate

Information disclosure in podman in github.com/containers/libpod

Information disclosure in podman in github.com/containers/libpod

Exploit probability 1.4%
Published June 4, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

3 explicit affected versions

Go github.com/containers/libpod
Go github.com/containers/libpod/v2
Go github.com/containers/podman/v2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-14370

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

View original source
Open Source Vulnerabilities GO-2024-2766

Information disclosure in podman in github.com/containers/libpod

View original source
Open Source Vulnerabilities GHSA-c3wv-qmjj-45r6

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

View original source

05 / REFERENCES

Further evidence