CVE-2018-10856
published 2018-07-03CVE-2018-10856: It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary…
PriorityP342high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
0.88%
55.0th percentile
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | — | — |
| github.com | containers_podman | >= 0 < 0.6.1 | 0.6.1 |
| libpod_project | libpod | < 0.6.1 | 0.6.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Podman Elevated Container Privileges in github.com/containers/podman
osv·2024-08-20
CVE-2018-10856 Podman Elevated Container Privileges in github.com/containers/podman
Podman Elevated Container Privileges in github.com/containers/podman
Podman Elevated Container Privileges in github.com/containers/podman
GHSA
Podman Elevated Container Privileges
ghsa·2022-05-13
CVE-2018-10856 [HIGH] CWE-732 Podman Elevated Container Privileges
Podman Elevated Container Privileges
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
OSV
Podman Elevated Container Privileges
osv·2022-05-13
CVE-2018-10856 [HIGH] Podman Elevated Container Privileges
Podman Elevated Container Privileges
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Red Hat
podman: Containers run as non-root users do not drop capabilities
vendor_redhat·2018-05-31·CVSS 5.3
CVE-2018-10856 [MEDIUM] CWE-250 podman: Containers run as non-root users do not drop capabilities
podman: Containers run as non-root users do not drop capabilities
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
It has been discovered that podman does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Package: podman (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-10856: libpod - It has been discovered that podman before version 0.6.1 does not drop capabiliti...
vendor_debian·2018·CVSS 5.3
CVE-2018-10856 [MEDIUM] CVE-2018-10856: libpod - It has been discovered that podman before version 0.6.1 does not drop capabiliti...
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Scope: local
bookworm: resolved
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10856 podman: Containers run as non-root users do not drop capabilities [fedora-all]
bugzilla·2018-06-18·CVSS 5.3
CVE-2018-10856 [MEDIUM] CVE-2018-10856 podman: Containers run as non-root users do not drop capabilities [fedora-all]
CVE-2018-10856 podman: Containers run as non-root users do not drop capabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2018-10856 podman: Containers run as non-root users do not drop capabilities
bugzilla·2018-06-18·CVSS 5.3
CVE-2018-10856 [MEDIUM] CVE-2018-10856 podman: Containers run as non-root users do not drop capabilities
CVE-2018-10856 podman: Containers run as non-root users do not drop capabilities
Podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Discussion:
Created podman tracking bugs for this issue:
Affects: fedora-all [bug 1592167]
---
Patch:
https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extras
Via RHSA-2018:2037 https://access.redhat.com/errata/RHSA-2018:2037
https://access.redhat.com/errata/RHSA-2018:2037https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10856https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24https://access.redhat.com/errata/RHSA-2018:2037https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10856https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24
2018-07-03
Published