漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Podman: WORKDIR symlink traversal vulnerability
Vulnerability Description
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
CWE-61
Vulnerability Title
Podman 后置链接漏洞
Vulnerability Description
Podman是Podman组织开源的一款用于在Linux系统上开发、管理和运行OCI容器的引擎。 Podman 3.0.0版本至5.7.1之前版本存在后置链接漏洞,该漏洞源于WORKDIR路径中包含符号链接,可能导致在主机文件系统上创建目录或修改所有权,触发竞争条件。
CVSS Information
N/A
Vulnerability Type
N/A