← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-1227

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:4.24%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
podman_project podman all
psgo_project psgo all
redhat developer_tools 1.0
redhat enterprise_linux_server_update_services_for_sap_solutions 8.6
redhat openshift_container_platform 4.0
redhat quay 3.0.0
redhat enterprise_linux 7.0, 8.0
redhat enterprise_linux_eus 8.6
redhat enterprise_linux_for_ibm_z_systems 7.0, 8.6
redhat enterprise_linux_for_power_little_endian 7.0, 8.6
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_aus 8.6
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.6
redhat enterprise_linux_server_tus 8.6
redhat enterprise_linux_workstation 7.0
fedoraproject fedora 34, 35

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.238%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2022-04-04T00:00:00
Published2022-04-29T15:45:00
Last Updated2024-08-02T23:55:24

LINK COPIED TO CLIPBOARD