CVE-2019-10152 is a path traversal vulnerability affecting Podman versions prior to 1.4.0, as well as specific versions of openSUSE and libpod_project. An attacker who has already compromised a container can leverage this flaw to read or write arbitrary files on the host system when an administrator attempts to copy files to or from the compromised container. Rated as High severity with a CVSS score of 7.2, successful exploitation requires local access to a container, high attack complexity, and user interaction, leading to high confidentiality and integrity impacts. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.0CPE matchmatch criteria | cpe:2.3:a:libpod_project:libpod:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.