CVE-2021-20199
Summary
| CVE | CVE-2021-20199 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-02 19:15:00 UTC |
| Updated | 2021-02-26 03:32:00 UTC |
| Description | Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| port: add ChildIP by giuseppe · Pull Request #206 · rootless-containers/rootlesskit · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| 1919050 – (CVE-2021-20199) CVE-2021-20199 podman: Remote traffic to rootless containers is seen as orginating from localhost |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Source IP always 127.0.0.1 in rootless Podman 1.8.0 · Issue #5138 · containers/podman · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| rootlessport: set source IP to slirp4netns device by giuseppe · Pull Request #9052 · containers/podman · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159458 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2021-1796)
- 160293 Oracle Enterprise Linux Security Update for podman (ELSA-2022-7954)
- 180303 Debian Security Update for rootlesskitlibpod (CVE-2021-20199)
- 239301 Red Hat Update for container-tools:rhel8 (RHSA-2021:1796)
- 240876 Red Hat Update for podman (RHSA-2022:7954)
- 501897 Alpine Linux Security Update for podman
- 751822 OpenSUSE Security Update for conmon, libcontainers-common, libseccomp, podman (openSUSE-SU-2022:23018-1)
- 752014 SUSE Enterprise Linux Security Update for conmon, libcontainers-common, libseccomp, podman (SUSE-SU-2022:23018-1)
- 752601 SUSE Enterprise Linux Security Update for libcontainers-common (SUSE-SU-2022:3312-1)
- 753592 SUSE Enterprise Linux Security Update for podman (SUSE-SU-2023:0187-1)
- 753659 SUSE Enterprise Linux Security Update for podman (SUSE-SU-2023:0326-1)
- 901065 Common Base Linux Mariner (CBL-Mariner) Security Update for podman (7329)
- 902632 Common Base Linux Mariner (CBL-Mariner) Security Update for podman (7329-1)
- 940208 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2021:1796)
- 940834 AlmaLinux Security Update for podman (ALSA-2022:7954)
- 960349 Rocky Linux Security Update for container-tools:rhel8 (RLSA-2021:1796)
- 982548 Go (go) Security Update for github.com/containers/podman/v3 (GHSA-grh6-q6m2-rh72)