REDHAT-BUG-2144989: Low severity containers podman vulnerability
This flaw was found in Buildah via podman,. > Type: information disclosure of a local absolute path > > Severity: very low. (A local path is not that sensitive information). > Feel free to just disregard this report if you think this issue has > too low importance. > > Summary: Podman may disclose the absolute path of an empty context dir > when running "podman --remote build -t test1 -f /tmp/Dockerfile > emptydir". The path could be logged in the container image. (The > lowest subdirectory of the absolute path might not be disclosed, see > discussion below) > > The issue was introduced in > https://github.com/containers/podman/pull/13531 > that went into the Podman release v4.1.0-rc1 >
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2144989?
The severity of REDHAT-BUG-2144989 is classified as very low.
What is the nature of the vulnerability in REDHAT-BUG-2144989?
The vulnerability in REDHAT-BUG-2144989 involves information disclosure of a local absolute path.
Which software is affected by REDHAT-BUG-2144989?
The affected software for REDHAT-BUG-2144989 is Containers Podman starting from version 4.1.0-rc1.
Is there a workaround for REDHAT-BUG-2144989?
Given the very low severity of REDHAT-BUG-2144989, it is generally recommended to evaluate the risks and possibly disregard this issue.
What is the impact of exploiting REDHAT-BUG-2144989?
The impact of exploiting REDHAT-BUG-2144989 mainly leads to the disclosure of a local path, which is not considered sensitive.