Low severity3.3NVD Advisory· Published Dec 8, 2022· Updated Jun 17, 2026
CVE-2022-4123
CVE-2022-4123
Description
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/containers/podman/v4Go | >= 4.1.0-rc1, <= 4.4.1 | — |
Affected products
15- Buildah/Buildahdescription
cpe:2.3:a:podman_project:podman:4.1.0:-:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:podman_project:podman:4.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.1.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.1.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.2.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:podman_project:podman:4.3.0:-:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-rprg-4v7q-87v7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-4123ghsaADVISORY
- github.com/containers/podman/commit/7934b77dd5372c22063686a218b8b48c2fcaca8cghsaWEB
- github.com/containers/podman/issues/13293ghsaWEB
- github.com/containers/podman/pull/13531ghsaWEB
- pkg.go.dev/vuln/GO-2022-1159ghsaWEB
News mentions
0No linked articles in our index yet.