FlawAtlas
Search the atlas
CVE-2022-4122 Moderate

Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman

Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman

Exploit probability 0.8%
Published August 21, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

3 explicit affected versions

Go github.com/containers/podman
Go github.com/containers/podman/v2
Go github.com/containers/podman/v3
Go github.com/containers/podman/v4
Go github.com/containers/podman/v4

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2022-4122

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

View original source
Open Source Vulnerabilities GO-2022-1151

Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman

View original source
Open Source Vulnerabilities GHSA-4crw-w8pw-2hmf

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

View original source

05 / REFERENCES

Further evidence