QID 375782

Date Published: 2021-11-23

QID 375782: Red Hat OpenShift Container Platform 3.11

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

A flaw was found in podman. File permissions for non-root users running in a privileged container are not correctly checked

Affected Products: Red Hat OpenShift Container Platform 3.11 Package Podman

This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root user inside the container

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Patch is not available yet. Refer to please check for more details.

    Vendor References

    CVEs related to QID 375782

    Software Advisories
    Advisory ID Software Component Link