Information disclosure in Podman - CVE-2020-14370
Published: September 23, 2020 / Updated: September 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way application processes environment variables with deprecated Varlink API or the Docker-compatible REST API. If multiple containers are created in a short duration, the environment variables from the first container gets leaked into subsequent containers. A remote user with control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
Affected software
Arch Linux
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Fedora
podman (Red Hat package)
podman (Alpine package)
crun
skopeo
podman
podman-remote
podman-tests
podman-docker
libcontainers-common
How to mitigate CVE-2020-14370
podman (Red Hat package) - update to 1.6.4-26.el7_9
crun - addressed in versions 0.15-5.fc31, 0.15-5.fc32, 0.15-5.fc33
skopeo - update to 1.2.0-3.fc33
podman - update to 1.6.4-36
podman-remote - update to 1.6.4-36
podman-tests - update to 1.6.4-36
podman-docker - update to 1.6.4-36
podman - addressed in versions 2.1.1-3.fc31, 2.1.1-7.fc32, 2.1.1-10.fc33
libcontainers-common - update to 20210626-150100.3.15.1
External References
Related Security Bulletins
- Information disclosure in Podman
- Arch Linux update for podman
- Information disclosure in podman (Alpine package)
- Red Hat Enterprise Linux 7 Extras update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- SUSE update for libcontainers-common
- Anolis OS update for podman
- Fedora 33 update for crun, podman, skopeo
- Fedora 32 update for crun, podman
- Fedora 31 update for crun, podman