Information disclosure in Podman - CVE-2021-3602

 

Information disclosure in Podman - CVE-2021-3602

Published: July 19, 2021


Vulnerability identifier: #VU54940
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3602
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to podman build command with the --isolation chroot flag includes environment variables from the host. A remote attacker with access to the container can obtain sensitive information from environment variables.


Affected software

Podman
buildah
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Fedora
crun
containernetworking-plugins
skopeo
containers-common
buildah
podman
libcontainers-common

How to mitigate CVE-2021-3602

Install updates from vendor's website.

Podman - update to 3.2.3
buildah - addressed in versions 1.16.8, 1.17.2, 1.19.9, 1.21.3
crun - update to 0.20.1-1.fc33
containernetworking-plugins - update to 1.0.0-0.2.rc1.fc33
skopeo - update to 1.3.1-1.fc33
containers-common - update to 1-20.fc33
buildah - addressed in versions 1.21.4-4.fc33, 1.21.4-4.fc34
podman - addressed in versions 3.2.3-1.fc33, 3.2.3-1.fc34
libcontainers-common - update to 20210626-150100.3.15.1

External References

Related Security Bulletins