CVE-2022-1227
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
Affected (20)
Products: Podman Project: Podman · Psgo Project: Psgo · Redhat: Developer Tools, Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Power Little Endian, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Workstation, Openshift Container Platform, Quay · +1 more
Show all products
Podman Project: Podman · Psgo Project: Psgo · Redhat: Developer Tools, Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Power Little Endian, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Workstation, Openshift Container Platform, Quay · Fedoraproject: Fedora
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0.0 | |
| Before 1.7.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 | |
| Version 7.0 | |
| Version 8.6 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 7.0 | |
| Version 4.0 | |
| Version 3.0.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Related CWEs
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-281
Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
References (8)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
ExploitIssue TrackingThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.