MEDIUM 5.5 Go

Podman Symlink Vulnerability

GHSA-r34v-gqmw-qvgj · CVE-2019-18466 · GO-2023-1942

Published · Modified

Description

An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.

Ready to move

Start Securing

Free, no credit card | First findings in minutes