CVE Vulnerabilities

CVE-2022-1227

Improper Privilege Management

Published: Apr 29, 2022 | Modified: Jun 28, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the podman top command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Podman Podman_project * 4.0.0 (excluding)
Psgo Psgo_project * 1.7.2 (excluding)
Red Hat Enterprise Linux 7 Extras RedHat podman-0:1.6.4-32.el7_9 *
Red Hat Enterprise Linux 8 RedHat container-tools:rhel8-8060020220401155929.2e213529 *
Red Hat Enterprise Linux 8 RedHat container-tools:3.0-8060020220419093427.3b538bd8 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat container-tools:2.0-8020020220420173758.28c38760 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat container-tools:3.0-8040020220419093313.c0c392d5 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat container-tools:rhel8-8040020220623181602.c0c392d5 *
Red Hat OpenShift Container Platform 4.6 RedHat podman-0:1.9.3-5.rhaos4.6.el8 *
Golang-github-containers-psgo Ubuntu impish *
Golang-github-containers-psgo Ubuntu kinetic *
Golang-github-containers-psgo Ubuntu lunar *
Golang-github-containers-psgo Ubuntu mantic *
Golang-github-containers-psgo Ubuntu trusty *
Golang-github-containers-psgo Ubuntu xenial *

Potential Mitigations

References