[GO-2023-1681] Time-of-check time-of-use race condition in github.com/containers/podman/v4
Severity
Medium
Affected Packages
1
Fixed Packages
1
CVEs
1
A Time-of-check Time-of-use (TOCTOU) flaw appears in this version of podman.
This issue may allow a malicious user to replace a normal file in a volume with
a symlink while exporting the volume, allowing for access to arbitrary files on
the host file system.
Package | Affected Version |
---|---|
pkg:golang/github.com/containers/podman/v4/utils | >= 4.4.1, < 4.4.2 |
Package | Fixed Version |
---|---|
pkg:golang/github.com/containers/podman/v4/utils | = 4.4.2 |
- ID
- GO-2023-1681
- Severity
- medium
- Severity from
- CVE-2023-0778
- URL
- https://pkg.go.dev/vuln/GO-2023-1681
- Published
-
2023-03-30T20:49:07
(17 months ago) - Modified
-
2024-05-14T19:19:00
(4 months ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Security Advisory | https://github.com/advisories/GHSA-qwqv-rqgf-8qh8 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:golang/github.com/containers/podman/v4/utils | github.com/containers/podman/v4 | utils | = 4.4.2 | |||
Affected | pkg:golang/github.com/containers/podman/v4/utils | github.com/containers/podman/v4 | utils | >= 4.4.1 < 4.4.2 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |