Information disclosure in podman (Red Hat package) - CVE-2022-2739
Published: August 22, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a missing patch for #VU47117 (CVE-2020-14370) in podman Red Hat package. A remote user with control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
Affected software
podman
podman-remote
podman-tests
podman-docker
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
How to mitigate CVE-2022-2739
podman - update to 1.6.4-36
podman-remote - update to 1.6.4-36
podman-tests - update to 1.6.4-36
podman-docker - update to 1.6.4-36