CVE-2019-10152

HIGH EPSS 36.6%
Published Jul 30, 20196y ago · Modified Jun 17, 20262w ago
7.2 CVSS 3.1
High
Find Similar
Published Jul 30, 2019 6y ago
Last Modified Jun 17, 2026 2w ago

Description

A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

CVSS Details

Base Score
7.2
Exploitability
0.8
Impact
5.8
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Changed
Confidentiality High
Integrity High
Availability None

Threat Intelligence

EPSS Exploit Probability
36.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-22 Path Traversal Resource Mgmt
CWE-59

Affected Products 2

VendorProductVersionRange
libpod_projectlibpod* <1.4.0
opensuseleap15.1any

References 5

  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.html
    Mailing ListThird Party Advisory
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152
    Issue TrackingPatchThird Party Advisory
  • github.com https://github.com/containers/libpod/blob/master/RELEASE_NOTES.md#140
    Release NotesThird Party Advisory
  • github.com https://github.com/containers/libpod/issues/3211
    Third Party Advisory
  • github.com https://github.com/containers/libpod/pull/3214
    Third Party Advisory

Remediation

  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152
    Issue TrackingPatchThird Party Advisory