CVE-2018-10856

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libpod_project:libpod:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-03 01:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-10856

Mitre link : CVE-2018-10856

CVE.ORG link : CVE-2018-10856


JSON object : View

Products Affected

libpod_project

  • libpod
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-250

Execution with Unnecessary Privileges