CVE-2022-4122
published 2022-12-08CVE-2022-4122: A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
PriorityP423medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.80%
52.4th percentile
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-containers-buildah | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | containers_podman_v4 | >= 0 < 4.5.0 | 4.5.0 |
| podman_project | podman | — | — |
| podman_project | podman | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
podman: Symlink error leads to information disclosure
vendor_redhat·2022-11-22·CVSS 5.3
CVE-2022-4122 [MEDIUM] CWE-59 podman: Symlink error leads to information disclosure
podman: Symlink error leads to information disclosure
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
A vulnerability was found in buildah and podman. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Statement: These bugs come about when "podman --remote build ..." is run, thus affecting buildah, but the bug itself needs to be fixed in podman, and ported to Buildah.
Package: buildah (Red Hat Enterprise Linux 7) - Out of support scope
Package: podman (Red Hat Enterprise Linux 7) - Out of support scope
Package: container-tools:3.0/podman (Red Hat Enterprise Linux 8) - Affected
Package: container-tools:4.0/podman (R
Debian
CVE-2022-4122: golang-github-containers-buildah - A vulnerability was found in buildah. Incorrect following of symlinks while read...
vendor_debian·2022·CVSS 5.3
CVE-2022-4122 [MEDIUM] CVE-2022-4122: golang-github-containers-buildah - A vulnerability was found in buildah. Incorrect following of symlinks while read...
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
osv·2024-08-21
CVE-2022-4122 Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
GHSA
Buildah (as part of Podman) vulnerable to Link Following
ghsa·2022-12-08
CVE-2022-4122 [MEDIUM] CWE-59 Buildah (as part of Podman) vulnerable to Link Following
Buildah (as part of Podman) vulnerable to Link Following
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
OSV
CVE-2022-4122: A vulnerability was found in buildah
osv·2022-12-08·CVSS 5.3
CVE-2022-4122 [MEDIUM] CVE-2022-4122: A vulnerability was found in buildah
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
OSV
Buildah (as part of Podman) vulnerable to Link Following
osv·2022-12-08
CVE-2022-4122 [MEDIUM] Buildah (as part of Podman) vulnerable to Link Following
Buildah (as part of Podman) vulnerable to Link Following
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-08
Published