Vulnerability Name:

CVE-2020-14370 (CCN-188707)

Assigned:2020-09-22
Published:2020-09-22
Updated:2022-11-07
Summary:An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
5.3 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-212
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-14370

Source: CCN
Type: Red Hat Bugzilla - Bug 1874268
(CVE-2020-14370) - CVE-2020-14370 podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1874268

Source: XF
Type: UNKNOWN
podman-cve202014370-info-disc(188707)

Source: CCN
Type: podman GIT Repository
Ensure DefaultEnvVariables is used in Specgen

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-76fcd0ba34

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-7b6058fec9

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-3a4b8fca5e

Vulnerable Configuration:Configuration 1:
  • cpe:/a:podman_project:podman:*:*:*:*:*:*:*:* (Version < 2.0.5)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:202014370
    V
    CVE-2020-14370
    2023-06-22
    oval:org.opensuse.security:def:7584
    P
    libcontainers-common-20230214-150500.2.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7862
    P
    podman-4.4.4-150500.1.4 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:119277
    P
    Security update for libcontainers-common (Moderate) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119728
    P
    Security update for libcontainers-common (Moderate) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:118782
    P
    Security update for libcontainers-common (Moderate) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119739
    P
    Security update for libcontainers-common (Moderate) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:118972
    P
    Security update for libcontainers-common (Moderate) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119826
    P
    Security update for libcontainers-common (Moderate) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:3247
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3000
    P
    MozillaFirefox-68.1.0-109.92.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94630
    P
    libcontainers-common-20210626-150400.1.3 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94877
    P
    podman-3.4.4-150400.2.14 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94706
    P
    libsmi-0.4.8-1.29 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1298
    P
    Security update for the Linux Kernel (Important)
    2022-03-30
    oval:org.opensuse.security:def:98958
    P
    Security update for conmon, libcontainers-common, libseccomp, podman (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:923
    P
    Security update for conmon, libcontainers-common, libseccomp, podman (Moderate)
    2022-02-25
    oval:org.opensuse.security:def:42308
    P
    Security update for conmon, libcontainers-common, libseccomp, podman (Moderate)
    2022-02-25
    oval:org.opensuse.security:def:994
    P
    Security update for conmon, libcontainers-common, libseccomp, podman (Moderate)
    2022-02-25
    oval:org.opensuse.security:def:101615
    P
    Security update for conmon, libcontainers-common, libseccomp, podman (Moderate)
    2022-02-25
    oval:org.opensuse.security:def:101684
    P
    Security update for conmon, libcontainers-common, libseccomp, podman (Moderate)
    2022-02-25
    oval:org.opensuse.security:def:113150
    P
    podman-3.3.1-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:68387
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:64637
    P
    Security update for fetchmail (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:66996
    P
    Security update for webkit2gtk3 (Important)
    2021-12-02
    oval:org.opensuse.security:def:106578
    P
    podman-3.3.1-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:96644
    P
    libjansson-devel-2.9-1.24 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:1970
    P
    python2-numpy-gnu-hpc-1.16.5-1.164 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101419
    P
    tomcat-9.0.36-3.24.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:71843
    P
    ipsec-tools-0.8.2-5.35 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101131
    P
    podman-2.1.1-4.28.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62387
    P
    podman-2.1.1-4.28.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:73661
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:1972
    P
    java-1_8_0-ibm-1.8.0_sr5.11-1.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70887
    P
    curl-7.60.0-1.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:1975
    P
    ntp-4.2.8p11-2.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:67091
    P
    Security update for p7zip (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:1980
    P
    gv-3.7.4-1.41 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:1982
    P
    java-1_8_0-ibm-1.8.0_sr5.30-3.16.2 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:70774
    P
    Security update for MozillaThunderbird (Important)
    2021-04-13
    oval:org.opensuse.security:def:74703
    P
    Security update for python3 (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:73782
    P
    Security update for bind (Important)
    2021-03-02
    oval:com.redhat.rhsa:def:20210531
    P
    RHSA-2021:0531: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
    2021-02-16
    oval:org.opensuse.security:def:70339
    P
    Security update for openvswitch (Important)
    2021-02-11
    oval:org.opensuse.security:def:70447
    P
    Security update for MozillaFirefox (Important)
    2021-01-29
    oval:org.opensuse.security:def:64525
    P
    Security update for mutt (Moderate)
    2021-01-22
    oval:org.opensuse.security:def:1960
    P
    libpmi0-17.11.5-4.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71727
    P
    supportutils-3.1.9-5.24.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1965
    P
    libnss_slurm2-20.02.3-1.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2620
    P
    Security update for podman (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2630
    P
    Security update for podman (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2610
    P
    Security update for buildah (Important)
    2020-12-02
    oval:org.opensuse.security:def:49717
    P
    texlive-12many on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68490
    P
    Security update for podman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49481
    P
    perl-MIME-Charset on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65053
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:75052
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:65110
    P
    Recommended update for ruby2.5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49558
    P
    libmad-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51065
    P
    Security update for podman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49402
    P
    flatpak on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49727
    P
    binutils-devel-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49644
    P
    libICE6-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49491
    P
    typelib-1_0-JavaScriptCore-4_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49613
    P
    avahi-autoipd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65143
    P
    Security update for podman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50993
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64153
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:49654
    P
    libXt6-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49623
    P
    flatpak on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75185
    P
    Security update for podman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51003
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74577
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:49548
    P
    libgme-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51055
    P
    Security update for podman (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49392
    P
    bluez on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:110880
    P
    Security update for podman (Moderate)
    2020-11-27
    oval:org.opensuse.security:def:110327
    P
    Security update for podman (Moderate)
    2020-11-26
    oval:org.opensuse.security:def:117599
    P
    Security update for podman (Moderate)
    2020-11-19
    oval:org.opensuse.security:def:97455
    P
    Security update for podman (Moderate)
    2020-11-19
    oval:org.opensuse.security:def:104145
    P
    Security update for podman (Moderate)
    2020-11-19
    oval:org.opensuse.security:def:90490
    P
    Security update for podman (Moderate)
    2020-11-19
    oval:org.opensuse.security:def:103010
    P
    Security update for podman (Moderate)
    2020-11-19
    oval:org.opensuse.security:def:108085
    P
    Security update for podman (Moderate)
    2020-11-19
    BACK
    podman_project podman *
    redhat enterprise linux 7.0
    redhat enterprise linux 8.0
    redhat openshift container platform 4.6
    fedoraproject fedora 31
    fedoraproject fedora 32
    fedoraproject fedora 33