VDB
BDU%3A2022-01715
BDU%3A2022-01715
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость среды выполнения контейнеров Containerd, связанная с недостатками процедуры аутентификации, позволяющая нарушителю раскрыть защищаемую информацию
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Novell Inc., Fedora Project, Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», Cloud Native Computing Foundation | Ubuntu, Suse Linux Enterprise Server, openSUSE Tumbleweed, Fedora, OpenSUSE Leap, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Micro, Альт 8 СП (запись в едином реестре российских программ №4305), Containerd |
Timeline
- Apr 4, 2022 CVE Published
- Sep 30, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- https://github.com/containerd/containerd/commit/10f428dac7cec44c864e1b830a4623af27a9fc70 url
- https://github.com/containerd/containerd/releases/tag/v1.4.13 url
- https://github.com/containerd/containerd/releases/tag/v1.5.10 url
- https://github.com/containerd/containerd/releases/tag/v1.6.1 url
- https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7 url
- https://packetstormsecurity.com/files/166421/containerd-Image-Volume-Insecure-Handling.html url
- https://www.debian.org/security/2022/dsa-5091 url
- https://security-tracker.debian.org/tracker/CVE-2022-23648 url
- https://ubuntu.com/security/CVE-2022-23648 url
- https://ubuntu.com/security/notices/USN-5311-1 url
- https://www.openwall.com/lists/oss-security/2022/03/02/1 url
- https://www.suse.com/security/cve/CVE-2022-23648.html url
- https://www.cybersecurity-help.cz/vdb/SB2022030722 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AUDQUQBZJGBWJPMRVB6QCCCRF7O3O4PA/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HFTS2EF3S7HNYSNZSEJZIJHPRU7OPUV3/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OCCARJ6FU4MWBTXHZNMS7NELPDBIX2VO/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2022-1221SE17MD url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2023-0131SE47MD url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- http://packetstormsecurity.com/files/166421/containerd-Image-Volume-Insecure-Handling.html url
…and 1 more