A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/containers/podman/v3(Go) | 0 | 3.4 | N/A |
| github.com/containers/psgo(Go) | 0 | 1.7.2 | N/A |
CVSS Metrics