UBUNTU-CVE-2022-4122
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-4122
Summary:
Details: A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
References: https://ubuntu.com/security/CVE-2022-4122, https://access.redhat.com/security/cve/CVE-2022-4122, https://bugzilla.redhat.com/show_bug.cgi?id=2144983, https://www.cve.org/CVERecord?id=CVE-2022-4122, https://github.com/advisories/GHSA-4crw-w8pw-2hmf, https://github.com/containers/podman/pull/16315, https://github.com/containers/podman/commit/c8eeab21cf0a4f670be0cd399dd06fd5d4e06dfe, https://github.com/containers/podman/commit/70e8f6243a661f2a1bb196190b852df0a6e5d91a
Affected packages
Package
Name: golang-github-containers-buildah
Purl: pkg:deb/ubuntu/golang-github-containers-buildah?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
