cbcvebase.
CVE-2023-0778
published 2023-03-27

CVE-2023-0778: A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while…

medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlibpod< libpod 4.3.1+ds1-7 (bookworm)libpod 4.3.1+ds1-7 (bookworm)
github.comcontainers_podman_v4>= 0 < 4.4.24.4.2
libpod_projectlibpod>= 0 < 4.3.1+ds1-74.3.1+ds1-7
msrccbl2_cri-o_1.22.3-10_on_cbl_mariner_2.0
msrccbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
osv6.8MEDIUM