CVE-2022-2989 describes an incorrect handling of supplementary groups in the Podman container engine, potentially leading to sensitive information disclosure or data modification. This vulnerability affects various Podman and Red Hat Enterprise Linux/OpenShift Container Platform products. With a CVSS score of 7.1 (HIGH), it requires local access and the ability to execute binary code within an affected container to exploit. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-2989
May 9, 2023Podman's incorrect handling of the supplementary groups may lead to data disclosure, modification
Sep 14, 2022An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Sep 13, 2022podman: possible information disclosure and modification
Aug 22, 2022