SB2023062006 - Insufficient verification of data authenticity in Podman



SB2023062006 - Insufficient verification of data authenticity in Podman

Published: June 20, 2023

Security Bulletin ID SB2023062006
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient verification of data authenticity (CVE-ID: N/A)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to implementation of changes that removed the need of k8s/pause, however podman play kube was still trying to fetch it. An attacker with ability to control the source of an image could trick the application into using the default untusted infra image.


Remediation

Install update from vendor's website.