cbcvebase.
CVE-2022-1227
published 2022-04-29

CVE-2022-1227: A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded…

PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.21%
89.8th percentile
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiangolang-github-containers-psgo< golang-github-containers-psgo 1.7.1+ds1-1 (bookworm)golang-github-containers-psgo 1.7.1+ds1-1 (bookworm)
debianlibpod< golang-github-containers-psgo 1.7.1+ds1-1 (bookworm)golang-github-containers-psgo 1.7.1+ds1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
github.comcontainers_podman_v3>= 0 < 3.43.4
github.comcontainers_psgo>= 0 < 1.7.21.7.2
libpod_projectlibpod>= 0 < 3.0.1+dfsg1-3+deb11u23.0.1+dfsg1-3+deb11u2
libpod_projectlibpod>= 0 < 3.4.7+ds1-13.4.7+ds1-1
msrccbl2_podman_4.1.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
podman_projectpodman< 4.0.04.0.0
psgo_projectpsgo< 1.7.21.7.2
psgo_projectpsgo
redhatdeveloper_tools
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solution

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.