VYPR

Go modules package

github.com/containers/podman/v2

pkg:golang/github.com/containers/podman/v2

Vulnerabilities (4)

  • CVE-2024-9407MedOct 1, 2024
    affected < 5.2.4fixed 5.2.4

    A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensi

  • CVE-2024-3056Aug 2, 2024
    affected <= 5.2.0

    A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exh

  • CVE-2020-14370Sep 23, 2020
    affected < 2.0.5fixed 2.0.5

    An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container wil

  • CVE-2020-1726Feb 11, 2020
    affected < 2.0.6fixed 2.0.6

    A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used