FlawAtlas
Search the atlas
CVE-2023-0778 Moderate

CVE-2023-0778

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Exploit probability 0.5%
Published March 27, 2023
Required by Not available
Last source change March 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown
Go github.com/containers/podman/v4
Go github.com/containers/podman/v4

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-0778

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

View original source
Open Source Vulnerabilities GHSA-qwqv-rqgf-8qh8

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

View original source
Open Source Vulnerabilities GO-2023-1681

A Time-of-check Time-of-use (TOCTOU) flaw appears in this version of podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

View original source

05 / REFERENCES

Further evidence