MEDIUM 5.3 Go
Information disclosure in podman
GHSA-c3wv-qmjj-45r6 · CVE-2020-14370 · GO-2024-2766
Published · Modified
Description
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-14370
- WEB https://github.com/containers/podman/commit/a7e864e6e7de894d4edde4fff00e53dc6a0b5074
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=1874268
- PACKAGE https://github.com/containers/podman
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G6BPCZX4ASKNONL3MSCK564IVXNYSKLP
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y74V7HGQBNLT6XECCSNZNFZIB7G7XSAR
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z4Y2FSGQWP4AFT5AZ6UBN6RKHVXUBRFV
Ready to move
Start Securing
Free, no credit card | First findings in minutes