A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2144983 | Issue Tracking Third Party Advisory |
https://github.com/containers/podman/pull/16315 | Patch Third Party Advisory |
Information
Published : 2022-12-08 08:15
Updated : 2022-12-12 07:48
NVD link : CVE-2022-4122
Mitre link : CVE-2022-4122
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
podman_project
- podman
fedoraproject
- fedora