Collected research
Podman API service listening on TCP can be used from websites
Demonstrates that a Podman TCP API bound only to localhost can still be driven by an arbitrary website. Browser-simple POST requests create a container with a host-directory bind mount and start it, yielding code execution as the API service's user.
Record
- Published by
- proofnet
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of proofnet, first published at the original source. Preserved copies are kept so the citation survives its host.