SB2023062011 - Ubuntu update for libpod
Published: June 20, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: N/A)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to implementation of changes that removed the need of k8s/pause, however podman play kube was still trying to fetch it. An attacker with ability to control the source of an image could trick the application into using the default untusted infra image.
Remediation
Install update from vendor's website.