cbcvebase.
CVE-2021-4024
published 2021-12-23

CVE-2021-4024: A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy`…

PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
1.06%
60.7th percentile
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlibpod< libpod 3.4.3+ds1-1 (bookworm)libpod 3.4.3+ds1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
github.comcontainers_podman_v3>= 0 < 3.4.33.4.3
libpod_projectlibpod>= 0 < 3.4.3+ds1-13.4.3+ds1-1
podman_projectpodman
podman_projectpodman>= 3.3.0 < 3.4.33.4.3
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.