Remote Command Execution Vulnerability in Podman Container by Nokia
CVE-2023-49565

Currently unrated

Key Information:

Vendor

Nokia

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2023-49565?

The cbis_manager Podman container contains a vulnerability that allows for remote command execution through the /api/plugins endpoint. The issue stems from improper sanitization of the HTTP headers X-FILENAME, X-PAGE, and X-FIELD, which are leveraged directly in the subprocess.Popen function without sufficient validation. This oversight permits remote attackers to inject malicious header values into HTTP requests, leading to arbitrary command execution on the host system. Since the web service operates with root privileges within the container, successful exploitation can grant attackers elevated access. Implementing firewall restrictions on the management network can help reduce exposure to such threats.

Affected Version(s)

CBIS,NCS CBIS 22, NCS 22.12, NCS 23.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-49565 : Remote Command Execution Vulnerability in Podman Container by Nokia