CVE-2020-1726

CVSS v3.1 5.9 (Medium)
59% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.21 % (59th)
0.21% Progress
Affected Products 3
Advisories 7

A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.

Weaknesses
CWE-552
Files or Directories Accessible to External Parties
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2020-02-11 20:15:12
(4 years ago)
Updated Date
2023-02-12 23:40:34
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Libpod Project Libpod 1.6.0 cpe:2.3:a:libpod_project:libpod:1.6.0:-

Configuration #2

    CPE23 From Up To
  Redhat Openshift Container Platform 4.3 cpe:2.3:a:redhat:openshift_container_platform:4.3
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...