Bug 1205673 - (CVE-2022-4123) VUL-1: CVE-2022-4123: buildah: Path disclosure
VUL-1: CVE-2022-4123: buildah: Path disclosure
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P4 - Low : Minor
: ---
Assigned To: Containers Team
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2022-11-23 08:41 UTC by Robert Frohl
Modified: 2023-01-19 12:00 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2022-11-23 08:41:59 UTC

This flaw was found in Buildah via podman,.
> Type: information disclosure of a local absolute path
> Severity: very low. (A local path is not that sensitive information).
> Feel free to just disregard this report if you think this issue has
> too low importance.
> Summary: Podman may disclose the absolute path of an empty context dir
> when running "podman --remote build -t test1 -f /tmp/Dockerfile
> emptydir". The path could be logged in the container image. (The
> lowest subdirectory of the absolute path might not be disclosed, see
> discussion below)
> The issue was introduced in
> https://github.com/containers/podman/pull/13531
> that went into the Podman release v4.1.0-rc1