cbcvebase.
CVE-2019-10152
published 2019-07-30

CVE-2019-10152: A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has…

PriorityP335high7.2CVSS 3.1
AVLACHPRLUIRSCCHIHAN
EPSS
0.46%
37.1th percentile
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianlibpod
github.comcontainers_podman>= 0 < 1.4.01.4.0
libpod_projectlibpod< 1.4.01.4.0
opensuseleap
podmanpodman

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.