CVEFinder.io

CVE-2022-4122

đŸ”ļ medium
🔍 Scan for this CVE
Summary

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS Score
5.3
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2022-12-08
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 19.7% of all 330,193 vulnerabilities in our database.

#265,260
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Apr 22, 2025
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-04-22
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 4

🔗 References 2

https://bugzilla.redhat.com/show_bug.cgi?id=2144983
Issue Tracking Third Party Advisory

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-55686 đŸ”ļ medium 5.3 - Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where... 2026-06-26
CVE-2026-35093 âš ī¸ high 8.8 0.0 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or ... 2026-04-01
CVE-2026-35094 â„šī¸ low 3.3 0.0 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl... 2026-04-01
CVE-2023-4134 đŸ”ļ medium 5.5 0.0 A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device... 2024-11-14
CVE-2024-3056 âš ī¸ high 7.7 0.4 A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur... 2024-08-02
CVE-2024-6290 âš ī¸ high 8.8 0.3 Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co... 2024-06-24
These CVEs affect the same products