Information disclosure in Podman - CVE-2021-4024

 

Information disclosure in Podman - CVE-2021-4024

Published: December 8, 2021


Vulnerability identifier: #VU58668
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4024
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the "podman machine" function. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Podman
Gentoo Linux
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Fedora
toolbox-tests
toolbox
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
buildah
buildah-tests
containers-common
conmon
container-selinux
podman
crit
criu
criu-devel
criu-libs
python3-criu
podman (Red Hat package)
podman-cni-config
podman-debuginfo
podman-docker
podman-remote
podman-remote-debuginfo
libslirp
libslirp-devel
python3-podman
app-containers/podman
podman-tests
podman-plugins
podman-gvproxy
podman-catatonit
cockpit-podman

How to mitigate CVE-2021-4024

Install updates from vendor's website.

Podman - update to 3.4.3
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-5.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.5-3.0.1
skopeo - update to 1.14.5-3.0.1
buildah - update to 1.33.11-1
buildah-tests - update to 1.33.11-1
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
podman - addressed in versions 3.4.4-1.fc34, 3.4.4-1.fc35
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
podman-cni-config - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-debuginfo - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-docker - update to 4.3.1-150400.4.11.1
podman-remote - update to 4.3.1-150400.4.11.1
podman-remote-debuginfo - update to 4.3.1-150400.4.11.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
app-containers/podman - update to 4.9.4
podman-tests - update to 4.9.4-18.0.1
podman-remote - update to 4.9.4-18.0.1
podman-plugins - update to 4.9.4-18.0.1
podman-gvproxy - update to 4.9.4-18.0.1
podman-catatonit - update to 4.9.4-18.0.1
podman - update to 4.9.4-18.0.1
podman-docker - update to 4.9.4-18.0.1
cockpit-podman - update to 84.1-1

External References

Related Security Bulletins