CVE-2022-4318
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.12 | |
| Version 4.12 | |
| Version 4.12 | |
| Version 4.12 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 9.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 36 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.11 | |
| Version 4.11 | |
| Version 4.11 | |
| Version 4.11 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
Related CWEs
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
CWE-913
Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
References (8)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Timeline
No history available yet.