Lucene search

K
cvelistRedhatCVELIST:CVE-2019-10152
HistoryJul 30, 2019 - 10:07 p.m.

CVE-2019-10152

2019-07-3022:07:23
CWE-59
CWE-22
redhat
www.cve.org
8

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.6%

A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

CNA Affected

[
  {
    "product": "podman",
    "vendor": "Podman",
    "versions": [
      {
        "status": "affected",
        "version": "fixed in 1.4.0"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.6%