FlawAtlas
Search the atlas
CVE-2020-1726 Moderate

Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod

Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod

Exploit probability 1.8%
Published August 20, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

Go github.com/containers/libpod
Go github.com/containers/libpod/v2
Go github.com/containers/podman
Go github.com/containers/podman/v2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-1726

A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.

View original source
Open Source Vulnerabilities GO-2023-1544

Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod

View original source
Open Source Vulnerabilities GHSA-vmhj-p9hw-vgrf

A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0.

View original source

05 / REFERENCES

Further evidence