#VU77535 Insufficient verification of data authenticity in Podman

 

#VU77535 Insufficient verification of data authenticity in Podman

Published: June 20, 2023


Vulnerability identifier: #VU77535
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Podman
Software vendor:
Container Projects

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to implementation of changes that removed the need of k8s/pause, however podman play kube was still trying to fetch it. An attacker with ability to control the source of an image could trick the application into using the default untusted infra image.


Remediation

Install updates from vendor's website.

External links