Information disclosure in Podman - CVE-2020-14370

 

Information disclosure in Podman - CVE-2020-14370

Published: September 23, 2020 / Updated: September 27, 2020


Vulnerability identifier: #VU47117
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14370
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way application processes environment variables with deprecated Varlink API or the Docker-compatible REST API. If multiple containers are created in a short duration, the environment variables from the first container gets leaked into subsequent containers. A remote user with control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.


Affected software

Podman
Arch Linux
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Fedora
podman (Red Hat package)
podman (Alpine package)
crun
skopeo
podman
podman-remote
podman-tests
podman-docker
libcontainers-common

How to mitigate CVE-2020-14370

Install updates from vendor's website.

Podman - update to 2.0.5
podman (Red Hat package) - update to 1.6.4-26.el7_9
crun - addressed in versions 0.15-5.fc31, 0.15-5.fc32, 0.15-5.fc33
skopeo - update to 1.2.0-3.fc33
podman - update to 1.6.4-36
podman-remote - update to 1.6.4-36
podman-tests - update to 1.6.4-36
podman-docker - update to 1.6.4-36
podman - addressed in versions 2.1.1-3.fc31, 2.1.1-7.fc32, 2.1.1-10.fc33
libcontainers-common - update to 20210626-150100.3.15.1

External References

Related Security Bulletins