5.3
CVSSv3

CVE-2020-14370

Published: 23/09/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An information disclosure vulnerability was found in containers/podman in versions prior to 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

podman project podman

redhat enterprise linux 7.0

redhat enterprise linux 8.0

redhat openshift container platform 4.6

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Synopsis Moderate: podman security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for podman is now available for Red Hat Enterprise Linux 7 ExtrasRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVS ...
Synopsis Moderate: container-tools:rhel8 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Mode ...
Synopsis Moderate: OpenShift Container Platform 461 package security update Type/Severity Security Advisory: Moderate Topic An update for jenkins-2-plugins, openshift-clients, podman, runc, and skopeo is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this upd ...
A flaw was discovered in Podman before upstream version 205 When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first containers will get leaked into subsequent containers An attacker who has control over those subsequent containers m ...