CVE-2022-4123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
08/12/2022
Last modified:
22/04/2025

Description

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:podman_project:podman:4.1.0:-:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.2.0:-:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:podman_project:podman:4.3.0:-:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*