CVE-2021-20199
Podman Origin Validation Error
5.9
MEDIUM
CVSS 3.1
EPSS 0.13%
Description
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
How to fix CVE-2021-20199
To remediate CVE-2021-20199, upgrade the affected package to a fixed version below.
- —upgrade to 3.0.0~rc2+dfsg1-2 or later
- —upgrade to 0.12.0-1 or later
- —upgrade to 3.0.0 or later
Is CVE-2021-20199 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 3.0.0~rc2+dfsg1-2
- from 0, < 0.12.0-1
- from 0, < 3.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |