Paul Holzinger
43fbde4e66
kube play: don't follow volume symlinks onto the host
...
For ConfigMap and Secret kube play volumes podman populates the data
from the yaml. However the volume content is not controlled by us and we
can be tricked following a symlink to a file on the host instead.
Fixes: CVE-2025-9566
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2025-09-04 16:18:35 +02:00
..
2024-08-19 11:41:28 +02:00
2025-09-01 12:33:04 +02:00
2025-09-01 12:33:04 +02:00
2025-09-01 12:33:04 +02:00
2025-09-01 12:33:04 +02:00
2022-12-15 13:39:56 +01:00
2025-09-01 12:33:04 +02:00
2025-04-08 15:23:08 -07:00
2024-01-04 11:53:38 +02:00
2025-01-07 15:48:53 +01:00
2025-09-04 16:18:35 +02:00
2025-07-23 15:53:39 -04:00
2025-01-07 15:48:53 +01:00
2025-06-26 19:37:14 +02:00
2025-09-01 12:33:04 +02:00
2025-06-26 19:37:15 +02:00
2025-09-01 12:33:04 +02:00
2025-06-23 08:23:31 -04:00
2025-09-01 12:33:04 +02:00
2025-07-18 13:57:11 -07:00
2024-02-02 11:02:43 -05:00
2025-09-01 12:33:04 +02:00
2025-06-26 19:37:15 +02:00
2025-06-26 19:37:15 +02:00
2025-05-06 06:24:13 +02:00
2025-09-01 12:33:04 +02:00
2025-03-31 12:27:55 -07:00
2025-09-01 12:33:04 +02:00
2022-07-08 08:54:47 +02:00
2025-04-30 19:43:13 +02:00
2025-09-01 12:33:04 +02:00
2025-09-01 12:33:04 +02:00
2025-05-30 14:47:13 -04:00
2025-02-17 14:32:34 -05:00
2025-09-01 16:04:15 +00:00
2024-02-20 08:06:18 -05:00
2025-09-01 12:33:04 +02:00
2025-09-01 12:33:04 +02:00