#VU70478 Input validation error in CRI-O - CVE-2022-4318
Published: December 23, 2022 / Updated: April 4, 2023
CRI-O
CRI-O
Description
The vulnerability allows a local user to bypass certain security restrictions.
The vulnerability exists due to improper input validation when handling newline characters in environment variables. A local user can create a specially crafted environment variable and add entries to a container's /etc/passwd. It is also possible to circumvent admission validation of username/UID by adding such an entry.