Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2739

Опубликовано: 19 авг. 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.

Отчет

This issue only affects a single version of podman, 1.6.4-32.el7_9, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8container-tools:3.0/podmanNot affected
Red Hat Enterprise Linux 8container-tools:4.0/podmanNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 9podmanNot affected
Red Hat Enterprise Linux 7 ExtraspodmanFixedRHSA-2022:611922.08.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=2116927podman: Security regression of CVE-2020-14370 due to source code management issue

EPSS

Процентиль: 33%
0.00132
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.

CVSS3: 7.5
github
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.

oracle-oval
больше 3 лет назад

ELSA-2022-20240: podman security update (MODERATE)

EPSS

Процентиль: 33%
0.00132
Низкий

5.3 Medium

CVSS3