CVE-2022-1227
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
- Podman Project Podman
- < 4.0.0
- Psgo Project Psgo
- < 1.7.2
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 4.2% (90th percentile)
- Weakness
- CWE-269, CWE-281
- NVD status
- Modified
- Published
- 2022-04-29
CVE-2022-1227 at NVD
2 known exploits for CVE-2022-1227
Proof-of-concept code and exploit modules indexed by Sploitus