cbcvebase.
CVE-2022-4318
published 2023-09-25

CVE-2022-4318: A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

Affected

14 ranges
VendorProductVersion rangeFixed in
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
github.comcri-o_cri-o>= 0 < 1.26.01.26.0
msrccbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0
msrccbl2_cri-o_1.22.3-1_on_cbl_mariner_2.0
redhatopenshift_container_platform_for_arm64
redhatopenshift_container_platform_for_arm64
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_ibm_z_systems
redhatopenshift_container_platform_ibm_z_systems