CVE-2018-10856

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/07/2018
Last modified:
09/10/2019

Description

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libpod_project:libpod:*:*:*:*:*:*:*:* 0.6.1 (excluding)