← Back

CVE-2022-2989

nvd nist
Published: Sep 13, 2022Modified: Jun 5, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

Affected (6)

Podman
2 products
Enterprise Linux
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 7.0
Version 8.0
Version 9.0
Redhat
Version 3.11
Version 4.0

References (4)

Source: secalert@redhat.com
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.