ZeroHour

CVE-2022-1227

PoC
CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

Vendors
podman projectpsgo projectredhatfedoraproject
Products
podman, psgo, developer tools, enterprise linux server update services for sap solutions, openshift container platform, quay, enterprise linux, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for power little endian, enterprise linux server, enterprise linux server aus
Weakness
CWE-281, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.