CVE-2020-14370

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
podman_projectpodman
𝑥
< 2.0.5
redhatopenshift_container_platform
4.6
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpod
bookworm
4.3.1+ds1-8+deb12u1
fixed
bullseye
3.0.1+dfsg1-3+deb11u5
fixed
sid
5.2.2+ds1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpod
bionic
dne
focal
dne
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
conmon
suse enterprise sap 15 SP3
2.0.30-150300.8.3.1
fixed
suse enterprise server 15 SP3
2.0.30-150300.8.3.1
fixed
libcontainers-common-20210626
suse enterprise desktop 15 SP3
150300.8.3.1
fixed
suse enterprise sap 15 SP3
150300.8.3.1
fixed
suse enterprise server 15 SP3
150300.8.3.1
fixed
libcontainers-common-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
libcontainers-default-policy-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
libcontainers-sles-mounts-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
libseccomp-devel
suse enterprise desktop 15 SP3
2.5.3-150300.10.5.1
fixed
suse enterprise sap 15 SP3
2.5.3-150300.10.5.1
fixed
suse enterprise server 15 SP3
2.5.3-150300.10.5.1
fixed
libseccomp2
suse enterprise desktop 15 SP3
2.5.3-150300.10.5.1
fixed
suse enterprise sap 15 SP3
2.5.3-150300.10.5.1
fixed
suse enterprise server 15 SP3
2.5.3-150300.10.5.1
fixed
podman
suse enterprise sap 15 SP1
2.1.1-4.28.1
fixed
suse enterprise sap 15 SP2
2.1.1-4.28.1
fixed
suse enterprise sap 15 SP3
2.1.1-4.28.1
fixed
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP1
2.1.1-4.28.1
fixed
suse enterprise server 15 SP2
2.1.1-4.28.1
fixed
suse enterprise server 15 SP3
2.1.1-4.28.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-cni-config
suse enterprise sap 15 SP1
2.1.1-4.28.1
fixed
suse enterprise sap 15 SP2
2.1.1-4.28.1
fixed
suse enterprise sap 15 SP3
2.1.1-4.28.1
fixed
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP1
2.1.1-4.28.1
fixed
suse enterprise server 15 SP2
2.1.1-4.28.1
fixed
suse enterprise server 15 SP3
2.1.1-4.28.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
podman-docker
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-remote
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podmansh
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
registries-conf-default-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed
registries-conf-suse-20240408
suse enterprise desktop 15 SP6
150600.1.1
fixed
suse enterprise desktop 15 SP7
150600.1.1
fixed
suse enterprise sap 15 SP6
150600.1.1
fixed
suse enterprise sap 15 SP7
150600.1.1
fixed
suse enterprise server 15 SP6
150600.1.1
fixed
suse enterprise server 15 SP7
150600.1.1
fixed