Insufficient verification of data authenticity in Podman - #VU77535

 

Insufficient verification of data authenticity in Podman - #VU77535

Published: June 20, 2023


Vulnerability identifier: #VU77535
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to implementation of changes that removed the need of k8s/pause, however podman play kube was still trying to fetch it. An attacker with ability to control the source of an image could trick the application into using the default untusted infra image.


Affected software

Podman
Ubuntu
podman (Ubuntu package)
podman-docker (Ubuntu package)

Remediation

Install updates from vendor's website.

Podman - update to 4.0.0 rc1
podman (Ubuntu package) - update to 3.4.4+ds1-1ubuntu1.22.04.1
podman-docker (Ubuntu package) - update to 3.4.4+ds1-1ubuntu1.22.04.1

External References

Related Security Bulletins