[GO-2023-1681] Time-of-check time-of-use race condition in github.com/containers/podman/v4

Severity Medium
Affected Packages 1
Fixed Packages 1
CVEs 1

A Time-of-check Time-of-use (TOCTOU) flaw appears in this version of podman.
This issue may allow a malicious user to replace a normal file in a volume with
a symlink while exporting the volume, allowing for access to arbitrary files on
the host file system.

Package Affected Version
pkg:golang/github.com/containers/podman/v4/utils >= 4.4.1, < 4.4.2
ID
GO-2023-1681
Severity
medium
Severity from
CVE-2023-0778
URL
https://pkg.go.dev/vuln/GO-2023-1681
Published
2023-03-30T20:49:07
(17 months ago)
Modified
2024-05-14T19:19:00
(4 months ago)
Other Advisories
Source # ID Name URL
Security Advisory https://github.com/advisories/GHSA-qwqv-rqgf-8qh8
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/github.com/containers/podman/v4/utils github.com/containers/podman/v4 utils = 4.4.2
Affected pkg:golang/github.com/containers/podman/v4/utils github.com/containers/podman/v4 utils >= 4.4.1 < 4.4.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...