Description
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
Published: 2022-04-29
Score: 8.8 High
EPSS: 33.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-66vw-v2x9-hw75 Podman publishes a malicious image to public registries
History

No history.

Subscriptions

Fedoraproject Fedora
Podman Project Podman
Psgo Project Psgo
Redhat Developer Tools Enterprise Linux Enterprise Linux Eus Enterprise Linux For Ibm Z Systems Enterprise Linux For Power Little Endian Enterprise Linux Server Enterprise Linux Server Aus Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Enterprise Linux Server Tus Enterprise Linux Server Update Services For Sap Solutions Enterprise Linux Workstation Openshift Openshift Container Platform Quay Rhel Eus Rhel Extras Other
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-02T23:55:24.597Z

Reserved: 2022-04-04T00:00:00.000Z

Link: CVE-2022-1227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-29T16:15:08.753

Modified: 2024-11-21T06:40:17.833

Link: CVE-2022-1227

cve-icon Redhat

Severity : Important

Publid Date: 2021-07-15T00:00:00Z

Links: CVE-2022-1227 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses