Bug 1919050 (CVE-2021-20199) - CVE-2021-20199 podman: Remote traffic to rootless containers is seen as orginating from localhost
Summary: CVE-2021-20199 podman: Remote traffic to rootless containers is seen as orgin...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-20199
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1922865 1922866 1924134 1924157
Blocks: 1918409
TreeView+ depends on / blocked
 
Reported: 2021-01-22 01:12 UTC by Sam Fowler
Modified: 2022-11-15 09:47 UTC (History)
22 users (show)

Fixed In Version: podman 3.0
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in podman. Rootless containers receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts) which impact containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. The highest threat from this vulnerability is to data integrity.
Clone Of:
Environment:
Last Closed: 2021-05-18 14:38:05 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:7954 0 None None None 2022-11-15 09:47:46 UTC

Description Sam Fowler 2021-01-22 01:12:09 UTC
Rootless containers run with Podman, in versions from 1.8.0 onward, receive all traffic with a sourceIP of 127.0.0.1 (including from remote hosts). This can impact containerized applications that trust localhost (127.0.01) connections by default and do not require authentication.


Upstream issue:

https://github.com/containers/podman/issues/5138

Comment 3 Sam Fowler 2021-02-01 00:03:19 UTC
Mitigation:

Configure containerized applications to require authentication for connections from all sources, including localhost.

Comment 4 Sam Fowler 2021-02-01 00:03:43 UTC
Created podman tracking bugs for this issue:

Affects: fedora-all [bug 1922865]

Comment 12 Eric Christensen 2021-02-18 17:10:17 UTC
Statement:

This issue does not affect Podman prior to version 1.8.0. Podman shipped in the following products are therefore not affected:

* Red Hat Enterprise Linux 7 Extras
* Red Hat Enterprise Linux 8 Container Tools stream 1.0
* Red Hat Enterprise Linux 8 Container Tools stream 2.0
* OpenShift Container Platform 3.11
* OpenShift Container Platform 4.1 to 4.5

Comment 13 Product Security DevOps Team 2021-05-18 14:38:05 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-20199

Comment 14 errata-xmlrpc 2021-05-18 15:07:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:1796 https://access.redhat.com/errata/RHSA-2021:1796

Comment 15 errata-xmlrpc 2022-11-15 09:47:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2022:7954 https://access.redhat.com/errata/RHSA-2022:7954


Note You need to log in before you can comment on or make changes to this bug.