Information disclosure in Podman - CVE-2021-3602
Published: July 19, 2021
Vulnerability identifier: #VU54940
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3602
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to podman build command with the --isolation chroot flag includes environment variables from the host. A remote attacker with access to the container can obtain sensitive information from environment variables.
Affected software
Podman
buildah
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Fedora
crun
containernetworking-plugins
skopeo
containers-common
buildah
podman
libcontainers-common
buildah
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Fedora
crun
containernetworking-plugins
skopeo
containers-common
buildah
podman
libcontainers-common
How to mitigate CVE-2021-3602
Install updates from vendor's website.
Podman - update to 3.2.3
buildah - addressed in versions 1.16.8, 1.17.2, 1.19.9, 1.21.3
crun - update to 0.20.1-1.fc33
containernetworking-plugins - update to 1.0.0-0.2.rc1.fc33
skopeo - update to 1.3.1-1.fc33
containers-common - update to 1-20.fc33
buildah - addressed in versions 1.21.4-4.fc33, 1.21.4-4.fc34
podman - addressed in versions 3.2.3-1.fc33, 3.2.3-1.fc34
libcontainers-common - update to 20210626-150100.3.15.1
buildah - addressed in versions 1.16.8, 1.17.2, 1.19.9, 1.21.3
crun - update to 0.20.1-1.fc33
containernetworking-plugins - update to 1.0.0-0.2.rc1.fc33
skopeo - update to 1.3.1-1.fc33
containers-common - update to 1-20.fc33
buildah - addressed in versions 1.21.4-4.fc33, 1.21.4-4.fc34
podman - addressed in versions 3.2.3-1.fc33, 3.2.3-1.fc34
libcontainers-common - update to 20210626-150100.3.15.1
External References
Related Security Bulletins
- Information disclosure in libpod
- Information disclosure in Buildah
- SUSE update for libcontainers-common
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:2.0 module
- Red Hat Enterprise Linux 8 update for the container-tools:3.0 module
- Fedora 33 update for containernetworking-plugins, containers-common, crun, podman, skopeo
- Fedora 34 update for buildah
- Fedora 33 update for buildah
- Fedora 34 update for podman