CVE-2022-1227 is a high-severity privilege escalation flaw in Podman, affecting fedoraproject, podman_project, psgo_project, and redhat. An attacker can exploit this by publishing a malicious image to a public registry. When a user downloads and runs 'podman top' on this image, the vulnerability triggers, granting the attacker access to the host filesystem. This can lead to information disclosure or denial of service. The vulnerability has a CVSS score of 8.8, indicating a high impact, but there is no known active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:* | ||
< 1.7.2CPE matchmatch criteria | cpe:2.3:a:psgo_project:psgo:*:*:*:*:*:go:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:* | ||
8.6CPE matchmatch criteria | cpe:2.3:a:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
CVE-2022-1227
May 10, 2022Podman publishes a malicious image to public registries
Apr 30, 2022A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem leading to information disclosure or denial of service.
Apr 12, 2022psgo: Privilege escalation in 'podman top'
Jul 15, 2021