CVE-2019-10152
HIGH EPSS 36.6%
Published Jul 30, 20196y ago · Modified Jun 17, 20262w ago
7.2 CVSS 3.1
Published Jul 30, 2019 6y ago
Last Modified Jun 17, 2026 2w ago
Description
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Changed
Confidentiality High
Integrity High
Availability None
Threat Intelligence
EPSS Exploit Probability
36.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 2
CWE-22 Path Traversal Resource Mgmt
CWE-59
Affected Products 2
| Vendor | Product | Version | Range |
|---|---|---|---|
| libpod_project | libpod | * | <1.4.0 |
| opensuse | leap | 15.1 | any |
References 5
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.html
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152
- github.com https://github.com/containers/libpod/blob/master/RELEASE_NOTES.md#140
- github.com https://github.com/containers/libpod/issues/3211
- github.com https://github.com/containers/libpod/pull/3214
Remediation
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152