CVE Vulnerabilities

CVE-2022-1227

Improper Preservation of Permissions

Published: Apr 29, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the podman top command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Podman Podman_project * 4.0.0 (excluding)
Psgo Psgo_project * 1.7.2 (excluding)
Red Hat Enterprise Linux 7 Extras RedHat podman-0:1.6.4-32.el7_9 *
Red Hat Enterprise Linux 8 RedHat container-tools:rhel8-8060020220401155929.2e213529 *
Red Hat Enterprise Linux 8 RedHat container-tools:3.0-8060020220419093427.3b538bd8 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat container-tools:2.0-8020020220420173758.28c38760 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat container-tools:3.0-8040020220419093313.c0c392d5 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat container-tools:rhel8-8040020220623181602.c0c392d5 *
Red Hat OpenShift Container Platform 4.6 RedHat podman-0:1.9.3-5.rhaos4.6.el8 *
Golang-github-containers-psgo Ubuntu impish *
Golang-github-containers-psgo Ubuntu kinetic *
Golang-github-containers-psgo Ubuntu lunar *
Golang-github-containers-psgo Ubuntu mantic *
Golang-github-containers-psgo Ubuntu trusty *
Golang-github-containers-psgo Ubuntu xenial *

References