{
  "threat_severity" : "Moderate",
  "public_date" : "2023-02-15T15:56:00Z",
  "bugzilla" : {
    "description" : "podman: symlink exchange attack in podman export volume",
    "id" : "2168256",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2168256"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-367",
  "details" : [ "A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.", "A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system." ],
  "acknowledgement" : "Red Hat would like to thank Hongliang Tian (Ant Group), Weijie Liu (Ant Group), XiaoFeng Wang (Indiana University Bloomington), and Zhi Li (Huazhong University of Science and Technology) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2023-05-16T00:00:00Z",
    "advisory" : "RHSA-2023:2758",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "container-tools:rhel8-8080020230321153727.0f77c1b7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2023-05-16T00:00:00Z",
    "advisory" : "RHSA-2023:2802",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "container-tools:4.0-8080020230217080101.8108cfbc"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.13",
    "release_date" : "2023-05-18T00:00:00Z",
    "advisory" : "RHSA-2023:1325",
    "cpe" : "cpe:/a:redhat:openshift:4.13::el8",
    "package" : "podman-3:4.4.1-3.rhaos4.13.el8"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "podman",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "container-tools:3.0/podman",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "podman",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Out of support scope",
    "package_name" : "podman",
    "cpe" : "cpe:/a:redhat:openshift:3.11"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-0778\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-0778\nhttps://github.com/advisories/GHSA-qwqv-rqgf-8qh8" ],
  "name" : "CVE-2023-0778",
  "csaw" : false
}