Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66vw-v2x9-hw75

Опубликовано: 30 апр. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Podman publishes a malicious image to public registries

Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

Пакеты

Наименование

github.com/containers/podman/v3

go
Затронутые версииВерсия исправления

< 3.4

3.4

Наименование

github.com/containers/psgo

go
Затронутые версииВерсия исправления

< 1.7.2

1.7.2

EPSS

Процентиль: 97%
0.32935
Средний

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-269
CWE-281

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

CVSS3: 8
redhat
почти 4 года назад

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

CVSS3: 8.8
nvd
около 3 лет назад

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

CVSS3: 8.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 8.8
debian
около 3 лет назад

A privilege escalation flaw was found in Podman. This flaw allows an a ...

EPSS

Процентиль: 97%
0.32935
Средний

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-269
CWE-281