REDHAT-BUG-1801152: Low severity podman vulnerability
podman incorrectly allows containers, when created, to populate volumes that already have existing data inside. A malicious container image may use this flaw to overwrite existing files in a volume, even if it is mounted in read-only mode. The attack is possible only the first time a volume is used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1801152?
The severity of REDHAT-BUG-1801152 is high, as it allows a malicious container image to overwrite existing files in a volume.
How do I fix REDHAT-BUG-1801152?
To fix REDHAT-BUG-1801152, ensure that containers are created in a manner that does not allow them to populate pre-existing volumes.
What is the impact of REDHAT-BUG-1801152 on container security?
The impact of REDHAT-BUG-1801152 on container security is significant, as it can lead to data loss or unauthorized access to files in mounted volumes.
Can REDHAT-BUG-1801152 be exploited in production environments?
Yes, REDHAT-BUG-1801152 can be exploited in production environments if proper volume management practices are not followed.
Which software versions are affected by REDHAT-BUG-1801152?
REDHAT-BUG-1801152 affects all versions of Podman that allow containers to populate existing volume data.