CVE-2018-10856
03.07.2018, 01:29
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.Enginsight
Vendor | Product | Version |
---|---|---|
libpod_project | libpod | 𝑥 < 0.6.1 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
- CWE-250 - Execution with Unnecessary PrivilegesThe software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
References