The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade podman-debuginfoUpgrade podmanUpgrade podman-docker | Aug 26, 2022 | Aug 22, 2022 |
| Oracle_linux | — | Upgrade podman-dockerUpgrade podman | Aug 23, 2022 | Aug 19, 2022 |
| Redhat_linux | — | Upgrade podman-dockerUpgrade podmanUpgrade podman-debuginfo | Aug 26, 2022 | Aug 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub