CVE-2021-20199
Description
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
Risk Information
Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.634
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update buildah-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update buildah-debugsource-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update buildah-tests-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update cockpit-podman-29-2.module+el8.4.0+10607+f4da7515.noarch.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update conmon-2.0.26-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update conmon-debugsource-2.0.26-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update container-selinux-2.158.0-1.module+el8.4.0+10607+f4da7515.noarch.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update containernetworking-plugins-0.9.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update containernetworking-plugins-debugsource-0.9.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update containers-common-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update crit-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update criu-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update criu-debugsource-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update crun-0.18-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update crun-debugsource-0.18-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update fuse-overlayfs-1.4.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update fuse-overlayfs-debugsource-1.4.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update libslirp-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update libslirp-debugsource-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update libslirp-devel-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update oci-seccomp-bpf-hook-1.2.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update oci-seccomp-bpf-hook-debugsource-1.2.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-catatonit-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-debugsource-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-docker-3.0.1-6.module+el8.4.0+10607+f4da7515.noarch.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-plugins-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-remote-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update podman-tests-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update python3-criu-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update runc-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update runc-debugsource-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update skopeo-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update skopeo-debugsource-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update skopeo-tests-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update slirp4netns-1.1.8-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update slirp4netns-debugsource-1.1.8-1.module+el8.4.0+10607+f4da7515.x86_64.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update toolbox-0.0.8-1.module+el8.4.0+10607+f4da7515.noarch.rpm | Linux |
| (RHSA-2021:1796) container-tools:rhel8 security, bug fix, and enhancement update udica-0.2.4-1.module+el8.4.0+10607+f4da7515.noarch.rpm | Linux |
| SUSE-SU-2022:23018-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libseccomp2-2.5.3-150300.10.5.1.x86_64.rpm | Linux |
| SUSE-SU-2022:23018-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libseccomp-devel-2.5.3-150300.10.5.1.x86_64.rpm | Linux |
| SUSE-SU-2022:23018-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libcontainers-common-20210626-150300.8.3.1.noarch.rpm | Linux |
| SUSE-SU-2022:23018-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libseccomp2-debuginfo-2.5.3-150300.10.5.1.x86_64.rpm | Linux |
| SUSE-SU-2022:23018-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) libseccomp-debugsource-2.5.3-150300.10.5.1.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234