MEDIUM 6.8 Go

Podman Time-of-check Time-of-use (TOCTOU) Race Condition

GHSA-qwqv-rqgf-8qh8 · CVE-2023-0778 · GO-2023-1681

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Ready to move

Start Securing

Free, no credit card | First findings in minutes