Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37052
HistorySep 16, 2022 - 6:34 a.m.

Information Disclosure

2022-09-1606:34:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
podman
vulnerability
information disclosure
containers
software
improper handling
supplementary groups
attacker access
arbitrary codes

0.0005 Low

EPSS

Percentile

17.8%

github.com/containers/podman is vulnerable to Information Disclosure. The vulnerability exists in multiple functions due to improper handling of the supplementary groups in the Podman container engine which allows an attacker to gain access to containers and execute arbitrary codes.