Insufficient verification of data authenticity in Podman - #VU77535
Published: June 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to implementation of changes that removed the need of k8s/pause, however podman play kube was still trying to fetch it. An attacker with ability to control the source of an image could trick the application into using the default untusted infra image.
Affected software
Ubuntu
podman (Ubuntu package)
podman-docker (Ubuntu package)
Remediation
podman (Ubuntu package) - update to 3.4.4+ds1-1ubuntu1.22.04.1
podman-docker (Ubuntu package) - update to 3.4.4+ds1-1ubuntu1.22.04.1