CVE-2022-4122
Moderate
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
Exploit probability
0.8%
Published
August 21, 2024
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
3 explicit affected versions
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2022-4122
View original source
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Open Source Vulnerabilities
GO-2022-1151
View original source
Buildah (as part of Podman) vulnerable to Link Following in github.com/containers/podman
Open Source Vulnerabilities
GHSA-4crw-w8pw-2hmf
View original source
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
05 / REFERENCES
Further evidence
- https://bugzilla.redhat.com/show_bug.cgi?id=2144983
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4122.json
- https://github.com/containers/podman/pull/16315
- https://nvd.nist.gov/vuln/detail/CVE-2022-4122
- https://github.com/advisories/GHSA-4crw-w8pw-2hmf
- https://github.com/containers/podman/commit/c8eeab21cf0a4f670be0cd399dd06fd5d4e06dfe