Vulnerability Details CVE-2018-10856
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.9%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 6.5
Products affected by CVE-2018-10856
-
cpe:2.3:a:libpod_project:libpod:-
-
cpe:2.3:a:libpod_project:libpod:0.2
-
cpe:2.3:a:libpod_project:libpod:0.2.1
-
cpe:2.3:a:libpod_project:libpod:0.2.2
-
cpe:2.3:a:libpod_project:libpod:0.3.1
-
cpe:2.3:a:libpod_project:libpod:0.3.2
-
cpe:2.3:a:libpod_project:libpod:0.3.3
-
cpe:2.3:a:libpod_project:libpod:0.3.4
-
cpe:2.3:a:libpod_project:libpod:0.3.5
-
cpe:2.3:a:libpod_project:libpod:0.4.1
-
cpe:2.3:a:libpod_project:libpod:0.4.2
-
cpe:2.3:a:libpod_project:libpod:0.4.3
-
cpe:2.3:a:libpod_project:libpod:0.4.4
-
cpe:2.3:a:libpod_project:libpod:0.5.1
-
cpe:2.3:a:libpod_project:libpod:0.5.2
-
cpe:2.3:a:libpod_project:libpod:0.5.3
-
cpe:2.3:a:libpod_project:libpod:0.5.4