Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4122

Опубликовано: 22 нояб. 2022
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

A vulnerability was found in buildah and podman. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

Отчет

These bugs come about when "podman --remote build ..." is run, thus affecting buildah, but the bug itself needs to be fixed in podman, and ported to Buildah.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7buildahOut of support scope
Red Hat Enterprise Linux 7podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:3.0/podmanAffected
Red Hat Enterprise Linux 8container-tools:4.0/podmanWill not fix
Red Hat Enterprise Linux 8container-tools:rhel8/podmanAffected
Red Hat OpenShift Container Platform 3.11podmanUnder investigation
Red Hat OpenShift Container Platform 4buildahAffected
Red Hat OpenShift Container Platform 4podmanUnder investigation
Red Hat Enterprise Linux 8.8 Extended Update Supportcontainer-toolsFixedRHSA-2024:207729.04.2024
Red Hat Enterprise Linux 9podmanFixedRHSA-2024:910212.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2144983podman: Symlink error leads to information disclosure

EPSS

Процентиль: 32%
0.00119
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.3
nvd
больше 2 лет назад

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.3
debian
больше 2 лет назад

A vulnerability was found in buildah. Incorrect following of symlinks ...

CVSS3: 5.3
github
больше 2 лет назад

Buildah (as part of Podman) vulnerable to Link Following

oracle-oval
7 месяцев назад

ELSA-2024-9102: podman security update (MODERATE)

EPSS

Процентиль: 32%
0.00119
Низкий

5.9 Medium

CVSS3