It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libpod | Libpod_project | * | 0.6.1 (excluding) |
Red Hat Enterprise Linux 7 Extras | RedHat | podman-0:0.6.1-3.git3e0ff12.el7 | * |