漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
Vulnerability Description
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Podman Container Tools Podman 信息泄露漏洞
Vulnerability Description
Podman Container Tools Podman是Podman Container Tools组织开源的一款用于管理 OCI 容器和 Pod 的工具。 Podman Container Tools Podman 1.8.1版本至5.8.4版本存在安全漏洞,该漏洞源于容器镜像中仅包含键而无值的环境变量可能被传递到容器,且使用星号(*)会导致所有主机环境变量传递至容器,可能导致恶意镜像渗漏所有Podman环境变量。
CVSS Information
N/A
Vulnerability Type
N/A