CVE-2019-10152
published 2019-07-30CVE-2019-10152: A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has…
PriorityP335high7.2CVSS 3.1
AVLACHPRLUIRSCCHIHAN
EPSS
0.46%
37.1th percentile
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | — | — |
| github.com | containers_podman | >= 0 < 1.4.0 | 1.4.0 |
| libpod_project | libpod | < 1.4.0 | 1.4.0 |
| opensuse | leap | — | — |
| podman | podman | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Podman Path Traversal Vulnerability leads to arbitrary file read/write in github.com/containers/podman
osv·2024-08-20
CVE-2019-10152 Podman Path Traversal Vulnerability leads to arbitrary file read/write in github.com/containers/podman
Podman Path Traversal Vulnerability leads to arbitrary file read/write in github.com/containers/podman
Podman Path Traversal Vulnerability leads to arbitrary file read/write in github.com/containers/podman
GHSA
Podman Path Traversal Vulnerability leads to arbitrary file read/write
ghsa·2022-05-24
CVE-2019-10152 [HIGH] CWE-22 Podman Path Traversal Vulnerability leads to arbitrary file read/write
Podman Path Traversal Vulnerability leads to arbitrary file read/write
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
OSV
Podman Path Traversal Vulnerability leads to arbitrary file read/write
osv·2022-05-24
CVE-2019-10152 [HIGH] Podman Path Traversal Vulnerability leads to arbitrary file read/write
Podman Path Traversal Vulnerability leads to arbitrary file read/write
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Red Hat
podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers
vendor_redhat·2019-05-29·CVSS 7.2
CVE-2019-10152 [HIGH] CWE-59 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers
podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
A path traversal vulnerability has been discovered in podman in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Statement: This issue does not affect the versions of podman as s
Debian
CVE-2019-10152: libpod - A path traversal vulnerability has been discovered in podman before version 1.4....
vendor_debian·2019·CVSS 7.2
CVE-2019-10152 [HIGH] CVE-2019-10152: libpod - A path traversal vulnerability has been discovered in podman before version 1.4....
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Scope: local
bookworm: resolved
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers
bugzilla·2019-05-30·CVSS 7.2
CVE-2019-10152 [HIGH] CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers
CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers
Podman does not properly resolve symlinks within containers, allowing for access to files on the host system when executing `podman cp`. Symlinked files inside containers are resolved on the host, not within the container.
Upstream Issue:
https://github.com/containers/libpod/issues/3211
Upstream Fix:
https://github.com/containers/libpod/pull/3214
Discussion:
Created podman tracking bugs for this issue:
Affects: fedora-all [bug 1715668]
---
Function copyBetweenHostAndContainer() in cmd/podman/cp.go does not properly restricts the destination path of the copy operation, allowing an attacker who has control of a container to copy/overwrite files in the ho
Bugzilla
CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers [fedora-all]
bugzilla·2019-05-30·CVSS 7.2
CVE-2019-10152 [HIGH] CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers [fedora-all]
CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2018-15664 docker: symlink-exchange race attacks in docker cp
bugzilla·2019-05-28·CVSS 7.5
CVE-2018-15664 [HIGH] CVE-2018-15664 docker: symlink-exchange race attacks in docker cp
CVE-2018-15664 docker: symlink-exchange race attacks in docker cp
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).
References:
https://seclists.org/oss-sec/2019/q2/131
https://bugzilla.suse.com/show_bug.cgi?id=1096726
https://bugzilla.novell.com/show_bug.cgi?id=1096726
Upstream Patch:
https://github.com/docker/docker/pull/39252
https://github.com/docker/docker/pull/5720
https://github.com/docker/docker/pull/6000
Discussion:
Created docker tracking bugs for this issue:
Affects: fedora-all
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152https://github.com/containers/libpod/blob/master/RELEASE_NOTES.md#140https://github.com/containers/libpod/issues/3211https://github.com/containers/libpod/pull/3214http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10152https://github.com/containers/libpod/blob/master/RELEASE_NOTES.md#140https://github.com/containers/libpod/issues/3211https://github.com/containers/libpod/pull/3214
2019-07-30
Published