An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NPodman Project Podman
APPPodman Projectwszystkie wersjeRed Hat Enterprise Linux
OSRedhat7.08.09.0Red Hat OpenShift Container Platform
APPRedhat3.114.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
Powiązane podatności
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓ten sam produkt
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam produkt
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam produkt
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam produkt
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam produkt
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE