CVE-2019-10152

A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
redhatCNA
7.2 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
libpod_projectlibpod
𝑥
< 1.4.0
opensuseleap
15.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
podman_projectpodman
𝑥
≤ 1.4.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
libpod
bookworm
4.3.1+ds1-8+deb12u1
fixed
bullseye
3.0.1+dfsg1-3+deb11u5
fixed
sid
5.2.2+ds1-2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
fuse-overlayfs
suse enterprise sap 15 SP1
0.4.1-3.3.8
fixed
suse enterprise sap 15 SP2
0.4.1-3.3.8
fixed
suse enterprise sap 15 SP3
0.4.1-3.3.8
fixed
suse enterprise sap 15 SP4
0.4.1-3.3.8
fixed
suse enterprise sap 15 SP5
0.4.1-3.3.8
fixed
suse enterprise sap 15 SP6
0.4.1-3.3.8
fixed
suse enterprise sap 15 SP7
0.4.1-3.3.8
fixed
suse enterprise server 15 SP1
0.4.1-3.3.8
fixed
suse enterprise server 15 SP2
0.4.1-3.3.8
fixed
suse enterprise server 15 SP3
0.4.1-3.3.8
fixed
suse enterprise server 15 SP4
0.4.1-3.3.8
fixed
suse enterprise server 15 SP5
0.4.1-3.3.8
fixed
suse enterprise server 15 SP6
0.4.1-3.3.8
fixed
suse enterprise server 15 SP7
0.4.1-3.3.8
fixed
fuse3
suse enterprise desktop 15 SP2
3.6.1-3.3.8
fixed
suse enterprise desktop 15 SP3
3.6.1-3.3.8
fixed
suse enterprise sap 15 SP1
3.6.1-3.3.8
fixed
suse enterprise sap 15 SP2
3.6.1-3.3.8
fixed
suse enterprise sap 15 SP3
3.6.1-3.3.8
fixed
suse enterprise server 15 SP1
3.6.1-3.3.8
fixed
suse enterprise server 15 SP2
3.6.1-3.3.8
fixed
suse enterprise server 15 SP3
3.6.1-3.3.8
fixed
libcontainers-common-20190401
suse enterprise desktop 15 SP2
3.3.5
fixed
suse enterprise desktop 15 SP3
3.3.5
fixed
suse enterprise sap 15 SP2
3.3.5
fixed
suse enterprise sap 15 SP3
3.3.5
fixed
suse enterprise server 15 SP2
3.3.5
fixed
suse enterprise server 15 SP3
3.3.5
fixed
libcontainers-common-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
libcontainers-default-policy-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
libcontainers-sles-mounts-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
libfuse3-3
suse enterprise desktop 15 SP2
3.6.1-3.3.8
fixed
suse enterprise desktop 15 SP3
3.6.1-3.3.8
fixed
suse enterprise sap 15 SP1
3.6.1-3.3.8
fixed
suse enterprise sap 15 SP2
3.6.1-3.3.8
fixed
suse enterprise sap 15 SP3
3.6.1-3.3.8
fixed
suse enterprise server 15 SP1
3.6.1-3.3.8
fixed
suse enterprise server 15 SP2
3.6.1-3.3.8
fixed
suse enterprise server 15 SP3
3.6.1-3.3.8
fixed
podman
suse enterprise sap 15 SP1
1.4.4-4.8.1
fixed
suse enterprise sap 15 SP2
1.4.4-4.8.1
fixed
suse enterprise sap 15 SP3
1.4.4-4.8.1
fixed
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP1
1.4.4-4.8.1
fixed
suse enterprise server 15 SP2
1.4.4-4.8.1
fixed
suse enterprise server 15 SP3
1.4.4-4.8.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-cni-config
suse enterprise sap 15 SP1
1.4.4-4.8.1
fixed
suse enterprise sap 15 SP2
1.4.4-4.8.1
fixed
suse enterprise sap 15 SP3
1.4.4-4.8.1
fixed
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP1
1.4.4-4.8.1
fixed
suse enterprise server 15 SP2
1.4.4-4.8.1
fixed
suse enterprise server 15 SP3
1.4.4-4.8.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
podman-docker
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-remote
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podmansh
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
registries-conf-default-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
registries-conf-suse-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
slirp4netns
suse enterprise sap 15 SP1
0.3.0-3.3.3
fixed
suse enterprise sap 15 SP2
0.3.0-3.3.3
fixed
suse enterprise sap 15 SP3
0.3.0-3.3.3
fixed
suse enterprise sap 15 SP4
0.3.0-3.3.3
fixed
suse enterprise server 15 SP1
0.3.0-3.3.3
fixed
suse enterprise server 15 SP2
0.3.0-3.3.3
fixed
suse enterprise server 15 SP3
0.3.0-3.3.3
fixed
suse enterprise server 15 SP4
0.3.0-3.3.3
fixed