Medium severity5.3NVD Advisory· Published Dec 8, 2022· Updated Jun 17, 2026
CVE-2022-4122
CVE-2022-4122
Description
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/containers/podman/v4Go | < 4.5.0 | 4.5.0 |
Affected products
6- cpe:2.3:a:podman_project:podman:4.3.0:-:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- buildah/buildahdescription
Patches
Vulnerability mechanics
References
5- github.com/containers/podman/pull/16315nvdPatchThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-4crw-w8pw-2hmfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-4122ghsaADVISORY
- github.com/containers/podman/commit/c8eeab21cf0a4f670be0cd399dd06fd5d4e06dfeghsaWEB
News mentions
0No linked articles in our index yet.