CVE-2021-20199
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.
- Podman Project Podman
- < 3.0.0
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 1.1% (63th percentile)
- Weakness
- CWE-346
- NVD status
- Modified
- Published
- 2021-02-02
CVE-2021-20199 at NVD
No indexed exploits for CVE-2021-20199 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-20199 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.