CVE-2019-10152

unknown
Published 2022-05-24 · Modified 2026-03-03
CVSS v3
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS v2
VIR risk

Description

A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-10152

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/containers/podman<1.4.01.4.0

References

Verify integrity in audit chain (admin only). AS-IS.