Vulnerability Details CVE-2022-2990
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.9%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2022-2990
-
cpe:2.3:a:buildah_project:buildah:-
-
cpe:2.3:a:buildah_project:buildah:0.1
-
cpe:2.3:a:buildah_project:buildah:0.10
-
cpe:2.3:a:buildah_project:buildah:0.11
-
cpe:2.3:a:buildah_project:buildah:0.12
-
cpe:2.3:a:buildah_project:buildah:0.14
-
cpe:2.3:a:buildah_project:buildah:0.15
-
cpe:2.3:a:buildah_project:buildah:0.16.0
-
cpe:2.3:a:buildah_project:buildah:0.2
-
cpe:2.3:a:buildah_project:buildah:0.3
-
cpe:2.3:a:buildah_project:buildah:0.4
-
cpe:2.3:a:buildah_project:buildah:0.5
-
cpe:2.3:a:buildah_project:buildah:0.6
-
cpe:2.3:a:buildah_project:buildah:0.7
-
cpe:2.3:a:buildah_project:buildah:0.8
-
cpe:2.3:a:buildah_project:buildah:0.9
-
cpe:2.3:a:buildah_project:buildah:1.0
-
cpe:2.3:a:buildah_project:buildah:1.1
-
cpe:2.3:a:buildah_project:buildah:1.10.0
-
cpe:2.3:a:buildah_project:buildah:1.10.1
-
cpe:2.3:a:buildah_project:buildah:1.11.0
-
cpe:2.3:a:buildah_project:buildah:1.11.1
-
cpe:2.3:a:buildah_project:buildah:1.11.2
-
cpe:2.3:a:buildah_project:buildah:1.11.3
-
cpe:2.3:a:buildah_project:buildah:1.11.4
-
cpe:2.3:a:buildah_project:buildah:1.11.5
-
cpe:2.3:a:buildah_project:buildah:1.11.6
-
cpe:2.3:a:buildah_project:buildah:1.12.0
-
cpe:2.3:a:buildah_project:buildah:1.13.0
-
cpe:2.3:a:buildah_project:buildah:1.13.1
-
cpe:2.3:a:buildah_project:buildah:1.13.2
-
cpe:2.3:a:buildah_project:buildah:1.14.0
-
cpe:2.3:a:buildah_project:buildah:1.14.1
-
cpe:2.3:a:buildah_project:buildah:1.14.10
-
cpe:2.3:a:buildah_project:buildah:1.14.11
-
cpe:2.3:a:buildah_project:buildah:1.14.2
-
cpe:2.3:a:buildah_project:buildah:1.14.3
-
cpe:2.3:a:buildah_project:buildah:1.14.5
-
cpe:2.3:a:buildah_project:buildah:1.14.6
-
cpe:2.3:a:buildah_project:buildah:1.14.7
-
cpe:2.3:a:buildah_project:buildah:1.14.8
-
cpe:2.3:a:buildah_project:buildah:1.14.9
-
cpe:2.3:a:buildah_project:buildah:1.15.0
-
cpe:2.3:a:buildah_project:buildah:1.15.1
-
cpe:2.3:a:buildah_project:buildah:1.15.2
-
cpe:2.3:a:buildah_project:buildah:1.16.0
-
cpe:2.3:a:buildah_project:buildah:1.16.1
-
cpe:2.3:a:buildah_project:buildah:1.16.2
-
cpe:2.3:a:buildah_project:buildah:1.16.3
-
cpe:2.3:a:buildah_project:buildah:1.16.4
-
cpe:2.3:a:buildah_project:buildah:1.16.5
-
cpe:2.3:a:buildah_project:buildah:1.16.6
-
cpe:2.3:a:buildah_project:buildah:1.16.7
-
cpe:2.3:a:buildah_project:buildah:1.16.8
-
cpe:2.3:a:buildah_project:buildah:1.17.0
-
cpe:2.3:a:buildah_project:buildah:1.17.1
-
cpe:2.3:a:buildah_project:buildah:1.17.2
-
cpe:2.3:a:buildah_project:buildah:1.18.0
-
cpe:2.3:a:buildah_project:buildah:1.19.0
-
cpe:2.3:a:buildah_project:buildah:1.19.1
-
cpe:2.3:a:buildah_project:buildah:1.19.2
-
cpe:2.3:a:buildah_project:buildah:1.19.3
-
cpe:2.3:a:buildah_project:buildah:1.19.4
-
cpe:2.3:a:buildah_project:buildah:1.19.6
-
cpe:2.3:a:buildah_project:buildah:1.19.7
-
cpe:2.3:a:buildah_project:buildah:1.19.8
-
cpe:2.3:a:buildah_project:buildah:1.19.9
-
cpe:2.3:a:buildah_project:buildah:1.2
-
cpe:2.3:a:buildah_project:buildah:1.20.0
-
cpe:2.3:a:buildah_project:buildah:1.20.1
-
cpe:2.3:a:buildah_project:buildah:1.21.0
-
cpe:2.3:a:buildah_project:buildah:1.21.1
-
cpe:2.3:a:buildah_project:buildah:1.21.2
-
cpe:2.3:a:buildah_project:buildah:1.21.3
-
cpe:2.3:a:buildah_project:buildah:1.21.4
-
cpe:2.3:a:buildah_project:buildah:1.22.0
-
cpe:2.3:a:buildah_project:buildah:1.22.1
-
cpe:2.3:a:buildah_project:buildah:1.22.2
-
cpe:2.3:a:buildah_project:buildah:1.22.3
-
cpe:2.3:a:buildah_project:buildah:1.22.4
-
cpe:2.3:a:buildah_project:buildah:1.23.0
-
cpe:2.3:a:buildah_project:buildah:1.23.1
-
cpe:2.3:a:buildah_project:buildah:1.23.2
-
cpe:2.3:a:buildah_project:buildah:1.23.3
-
cpe:2.3:a:buildah_project:buildah:1.23.4
-
cpe:2.3:a:buildah_project:buildah:1.24.0
-
cpe:2.3:a:buildah_project:buildah:1.24.1
-
cpe:2.3:a:buildah_project:buildah:1.24.2
-
cpe:2.3:a:buildah_project:buildah:1.24.3
-
cpe:2.3:a:buildah_project:buildah:1.25.0
-
cpe:2.3:a:buildah_project:buildah:1.25.1
-
cpe:2.3:a:buildah_project:buildah:1.3
-
cpe:2.3:a:buildah_project:buildah:1.4
-
cpe:2.3:a:buildah_project:buildah:1.5
-
cpe:2.3:a:buildah_project:buildah:1.6
-
cpe:2.3:a:buildah_project:buildah:1.7
-
cpe:2.3:a:buildah_project:buildah:1.7.1
-
cpe:2.3:a:buildah_project:buildah:1.7.2
-
cpe:2.3:a:buildah_project:buildah:1.7.3
-
cpe:2.3:a:buildah_project:buildah:1.8.0
-
cpe:2.3:a:buildah_project:buildah:1.8.1
-
cpe:2.3:a:buildah_project:buildah:1.8.2
-
cpe:2.3:a:buildah_project:buildah:1.8.3
-
cpe:2.3:a:buildah_project:buildah:1.8.4
-
cpe:2.3:a:buildah_project:buildah:1.9.0
-
cpe:2.3:a:buildah_project:buildah:1.9.1
-
cpe:2.3:a:buildah_project:buildah:1.9.2
-
cpe:2.3:a:redhat:openshift_container_platform:4.0
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0
-
cpe:2.3:o:redhat:enterprise_linux:9.0