PT-2026-108794 · Red Hat · Red Hat Build Of Podman Desktop+9
CVSS v3.1
9.3
Critical
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H |
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Build Of Podman Desktop
Red Hat Certification Program For Red Hat Enterprise Linux 9
Red Hat Edge Manager 1
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Hardened Images
Red Hat Openshift Container Platform 4
Red Hat Openshift Dev Spaces
Red Hat Openstack Platform 18.0