Path traversal in Podman - CVE-2019-10152
Published: September 2, 2019
Vulnerability details
The vulnerability allows a local attacker to perform directory traversal attacks.
The vulnerability exists due to the software does not properly resolve symlinks within containers. A local authenticated attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power
Opensuse
Fedora
podman
How to mitigate CVE-2019-10152
podman - addressed in versions 1.4.0-1.fc29, 1.4.0-1.fc30, 1.4.0-2.fc29, 1.4.0-2.fc30