Improper Authorization Affecting podman-catatonit package, versions *


Severity

Recommended
medium

Based on CentOS security rating.

Threat Intelligence

EPSS
0.05% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-CENTOS8-PODMANCATATONIT-8817194
  • published28 Feb 2025
  • disclosed26 Nov 2024

Introduced: 26 Nov 2024

CVE-2024-8676  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

There is no fixed version for Centos:8 podman-catatonit.

NVD Description

Note: Versions mentioned in the description apply only to the upstream podman-catatonit package and not the podman-catatonit package as distributed by Centos. See How to fix? for Centos:8 relevant fixed versions and status.

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the validations run on the pod spec, verifying that the pod has access to the mounts it specifies are not applicable to a restored container. This flaw allows a malicious user to trick CRI-O into restoring a pod that doesn't have access to host mounts. The user needs access to the kubelet or cri-o socket to call the restore endpoint and trigger the restore.

CVSS Base Scores

version 3.1