CVE-2020-14370
published 2020-09-23CVE-2020-14370: An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible…
PriorityP430medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
1.40%
69.6th percentile
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | < libpod 2.0.6+dfsg1-1 (bookworm) | libpod 2.0.6+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | containers_libpod_v2 | >= 0 < 2.0.5 | 2.0.5 |
| github.com | containers_podman_v2 | >= 0 < 2.0.5 | 2.0.5 |
| libpod_project | libpod | >= 0 < 2.0.6+dfsg1-1 | 2.0.6+dfsg1-1 |
| libpod_project | libpod | >= 0 < 2.0.6+dfsg1-1 | 2.0.6+dfsg1-1 |
| podman_project | podman | < 2.0.5 | 2.0.5 |
| podman_project | podman | — | — |
| podman_project | podman | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Information disclosure in podman in github.com/containers/libpod
osv·2024-06-04
CVE-2020-14370 Information disclosure in podman in github.com/containers/libpod
Information disclosure in podman in github.com/containers/libpod
Information disclosure in podman in github.com/containers/libpod
OSV
Information disclosure in podman
osv·2024-04-24
CVE-2020-14370 [MEDIUM] Information disclosure in podman
Information disclosure in podman
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
GHSA
Information disclosure in podman
ghsa·2024-04-24
CVE-2020-14370 [MEDIUM] CWE-200 Information disclosure in podman
Information disclosure in podman
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
GHSA
GHSA-cqvr-p82r-76m9: The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing th
ghsa_unreviewed·2022-09-02·CVSS 5.3
CVE-2022-2739 [MEDIUM] CWE-200 GHSA-cqvr-p82r-76m9: The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing th
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.
OSV
CVE-2020-14370: An information disclosure vulnerability was found in containers/podman in versions before 2
osv·2020-09-23·CVSS 5.3
CVE-2020-14370 [MEDIUM] CVE-2020-14370: An information disclosure vulnerability was found in containers/podman in versions before 2
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
Red Hat
podman: Security regression of CVE-2020-14370 due to source code management issue
vendor_redhat·2022-08-19·CVSS 5.3
CVE-2022-2739 [MEDIUM] CWE-312 podman: Security regression of CVE-2020-14370 due to source code management issue
podman: Security regression of CVE-2020-14370 due to source code management issue
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.
Statement: This issue only affects
Red Hat
podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API
vendor_redhat·2020-09-22·CVSS 5.3
CVE-2020-14370 [MEDIUM] CWE-212 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API
podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
An information disclosure flaw was found in containers/podman. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from
Debian
CVE-2020-14370: libpod - An information disclosure vulnerability was found in containers/podman in versio...
vendor_debian·2020·CVSS 5.3
CVE-2020-14370 [MEDIUM] CVE-2020-14370: libpod - An information disclosure vulnerability was found in containers/podman in versio...
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
Scope: local
bookworm: resolved (fixed in 2.0.6+dfsg1-1)
bullseye: resolved (fixed in 2.0.6+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API [fedora-all]
bugzilla·2020-09-22·CVSS 5.3
CVE-2020-14370 [MEDIUM] CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API [fedora-all]
CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
Bugzilla
CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API
bugzilla·2020-08-31·CVSS 5.3
CVE-2020-14370 [MEDIUM] CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API
CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API
A flaw was discovered in Podman before upstream version 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first containers will get leaked into subsequent containers. An attacker who has control over those subsequent containers may get access to secrets shared with previous containers through environment variables.
Discussion:
The flaw lies in pkg/spec/spec.go:createConfigToOCISpec() function, where the variable DefaultEnvVariables of the env package is used and modified without making a copy of it. Thus when creating multiple containers in such
https://bugzilla.redhat.com/show_bug.cgi?id=1874268https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6BPCZX4ASKNONL3MSCK564IVXNYSKLP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y74V7HGQBNLT6XECCSNZNFZIB7G7XSAR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z4Y2FSGQWP4AFT5AZ6UBN6RKHVXUBRFV/https://bugzilla.redhat.com/show_bug.cgi?id=1874268https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6BPCZX4ASKNONL3MSCK564IVXNYSKLP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y74V7HGQBNLT6XECCSNZNFZIB7G7XSAR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z4Y2FSGQWP4AFT5AZ6UBN6RKHVXUBRFV/
2020-09-23
Published