V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-2990
DEB
High

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or pos…

CVSS
7.1
High
EPSS
0.00
p23
Published
2022-01-01
Updated
2022-01-01
Description

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

Tags · CWE
CWE-842
Affected products
Buildah < 1.27.1
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.003 · p23
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
buildahTracked
buildahTracked
golang-github-containers-buildahTracked
golang-github-containers-buildahTracked
golang-github-containers-buildahTracked
golang-github-containers-buildahTracked
golang-github-containers-buildahTracked
golang-github-containers-buildahTracked
golang-github-containers-buildahTracked
podmanTracked
buildah*Tracked
enterprise_linux*Tracked
openshift_container_platform*Tracked
Source databases
DEB
CVE
RED
UBU