HIGH 8.8 Go
Podman Elevated Container Privileges
GHSA-wp7w-vx86-vj9h · CVE-2018-10856 · GO-2023-1962
Published · Modified
Description
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2018-10856
- WEB https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24
- WEB https://access.redhat.com/errata/RHSA-2018:2037
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10856
- PACKAGE https://github.com/containers/podman
Ready to move
Start Securing
Free, no credit card | First findings in minutes