#VU20502 Path traversal in Podman - CVE-2019-10152
Published: September 2, 2019
Podman
Container Projects
Description
The vulnerability allows a local attacker to perform directory traversal attacks.
The vulnerability exists due to the software does not properly resolve symlinks within containers. A local authenticated attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.