#VU77535 Insufficient verification of data authenticity in Podman
Published: June 20, 2023
Podman
Container Projects
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to implementation of changes that removed the need of k8s/pause, however podman play kube was still trying to fetch it. An attacker with ability to control the source of an image could trick the application into using the default untusted infra image.