VYPR
High severity7.8NVD Advisory· Published Sep 25, 2023· Updated Jun 17, 2026

CVE-2022-4318

CVE-2022-4318

Description

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/cri-o/cri-oGo
< 1.26.01.26.0

Affected products

16
  • cpe:/a:redhat:openshift:4.11::el8+ 5 more
    • cpe:/a:redhat:openshift:4.11::el8range: 0:1.24.4-10.rhaos4.11.git1ed5ac5.el8
    • cpe:/a:redhat:openshift:4.12::el8range: 0:1.25.2-9.rhaos4.12.git0a083f9.el9
    • cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_power:4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_power:4.12:*:*:*:*:*:*:*
  • cpe:/o:redhat:enterprise_linux:9
  • cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:a:kubernetes:cri-o:-:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.11:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.12:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.11:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.12:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.26.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.