GHSA-rh5f-2w6r-q7vj

    Dashboard / Vulnerabilities / GHSA-rh5f-2w6r-q7vj

    GHSA-rh5f-2w6r-q7vj

    Published: 24 May 2022Last Modified: 20 Aug 2024

    Summary: Podman Path Traversal Vulnerability leads to arbitrary file read/write

    Details: A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

    Affected packages

    Package

    Name: github.com/containers/podman

    Purl: pkg:golang/github.com/containers/podman

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.4.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rh5f-2w6r-q7vj | CVE-DB