View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2018-10856 severity moderate: SUSE including 45 source package names (podman, podman-0.8.5-3.3.1, …), 65 product×package rows across 27 product lines (SUSE CaaS Platform 3.0, SUSE CaaS Platform 4.0, … (27 product lines)): Fixed 50, Known Not Affected 15.
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.