Podman is a tool for managing OCI containers and pods. A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
{ "nvd_published_at": "2022-04-29T16:15:00Z", "cwe_ids": [ "CWE-269", "CWE-281" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-05-03T06:15:16Z" }