[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-27651":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T20:55:29.923Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":131,"aliases":132,"duplicate_of":9,"upstream":135,"downstream":136,"duplicates":163,"related":164,"reserved_at":9,"published_at":174,"modified_at":175,"state":176,"summary":177,"references_raw":186,"kevs":255,"epss":256,"epss_history":259,"metrics":522,"affected":533},"CVE-2022-27651","A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-276","Incorrect Default Permissions","During installation, installed file permissions are set to allow anyone to modify those files.","weakness","Draft","Base","Medium",[20,68,127],{"id":21,"name":22,"techniques":23},"CAPEC-1","Accessing Functionality Not Properly Constrained by ACLs",[24],{"id":25,"name":26,"tactics":27,"countermeasures":43},"T1574.010","Services File Permissions Weakness",[28,31,34,37,40],{"id":29,"name":30},"TA0110","Persistence",{"id":32,"name":33},"TA0111","Privilege Escalation",{"id":35,"name":36},"TA0030","Defense Evasion",{"id":38,"name":39},"TA0005","Stealth",{"id":41,"name":42},"TA0104","Execution",[44,49,53,58,63],{"id":45,"name":46,"tactic":47},"D3-SWI","Software Inventory",{"name":48},"Model",{"id":50,"name":51,"tactic":52},"D3-AVE","Asset Vulnerability Enumeration",{"name":48},{"id":54,"name":55,"tactic":56},"D3-SBV","Service Binary Verification",{"name":57},"Detect",{"id":59,"name":60,"tactic":61},"D3-SU","Software Update",{"name":62},"Harden",{"id":64,"name":65,"tactic":66},"D3-RS","Restore Software",{"name":67},"Restore",{"id":69,"name":70,"techniques":71},"CAPEC-127","Directory Indexing",[72],{"id":73,"name":74,"tactics":75,"countermeasures":79},"T1083","File and Directory Discovery",[76],{"id":77,"name":78},"TA0102","Discovery",[80,84,88,93,98,102,106,111,115,119,123],{"id":81,"name":82,"tactic":83},"D3-FA","File Analysis",{"name":57},{"id":85,"name":86,"tactic":87},"D3-FIM","File Integrity Monitoring",{"name":57},{"id":89,"name":90,"tactic":91},"D3-FEV","File Eviction",{"name":92},"Evict",{"id":94,"name":95,"tactic":96},"D3-DF","Decoy File",{"name":97},"Deceive",{"id":99,"name":100,"tactic":101},"D3-FE","File Encryption",{"name":62},{"id":103,"name":104,"tactic":105},"D3-RF","Restore File",{"name":67},{"id":107,"name":108,"tactic":109},"D3-LFP","Local File Permissions",{"name":110},"Isolate",{"id":112,"name":113,"tactic":114},"D3-CF","Content Filtering",{"name":110},{"id":116,"name":117,"tactic":118},"D3-RFAM","Remote File Access Mediation",{"name":110},{"id":120,"name":121,"tactic":122},"D3-CQ","Content Quarantine",{"name":110},{"id":124,"name":125,"tactic":126},"D3-CM","Content Modification",{"name":110},{"id":128,"name":129,"techniques":130},"CAPEC-81","Web Server Logs Tampering",[],[],[133,134],"GHSA-c3g4-w6cv-6v7h","GO-2022-0417",[],[137,139,141,143,145,147,149,151,153,155,157,159,161],{"_key":138},"RHSA-2022:1407",{"_key":140},"RHSA-2022:1565",{"_key":142},"RHSA-2022:1566",{"_key":144},"SUSE-SU-2022:3480-1",{"_key":146},"SUSE-SU-2022:1437-1",{"_key":148},"SUSE-SU-2022:2680-1",{"_key":150},"OPENSUSE-SU-2024:11964-1",{"_key":152},"MGASA-2023-0213",{"_key":154},"DEBIAN-CVE-2022-27651",{"_key":156},"RHSA-2022:4651",{"_key":158},"RHSA-2022:4816",{"_key":160},"UBUNTU-CVE-2022-27651",{"_key":162},"RHSA-2022:1762",[],[165,166,167,168,169,170,172],{"_key":152},{"_key":144},{"_key":146},{"_key":148},{"_key":150},{"_key":171},"CGA-GPR2-42C3-43RF",{"_key":173},"CGA-92XM-329H-8G38","2022-04-04T19:45:44.000Z","2024-08-03T05:32:59.789Z","Modified",{"cisa_kev":178,"cisa_ransomware":178,"cisa_vendor":9,"epss_severity":179,"epss_score":180,"severity":181,"severity_score":182,"severity_version":183,"severity_source":184,"severity_vector":185,"severity_status":176},false,"low",0.00181,"medium",6.8,"v3.1","nvd","CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",[187,197,201,207,213,217,221,226,230,234,239,243,247,251],{"url":188,"sources":189,"tags":192},"https://bugzilla.redhat.com/show_bug.cgi?id=2066840",[190,184,191],"cve.org","osv_go",[193,194,195,196],"X Refsource MISC","Issue Tracking","Third Party Advisory","WEB",{"url":198,"sources":199,"tags":200},"https://github.com/containers/buildah/security/advisories/GHSA-c3g4-w6cv-6v7h",[190,184,191],[193,195,196],{"url":202,"sources":203,"tags":204},"https://github.com/containers/buildah/commit/e7e55c988c05dd74005184ceb64f097a0cfe645b",[190,184,191],[193,205,195,196,206],"Patch","FIX",{"url":208,"sources":209,"tags":210},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2VWH6X6HOFPO6HTESF42HIJZEPXSWVIO/",[190,184],[211,212],"Vendor Advisory","X Refsource FEDORA",{"url":214,"sources":215,"tags":216},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7NETC7I6RTMMBRJJQVJOJUPDK4W4PQSJ/",[190,184],[211,212],{"url":218,"sources":219,"tags":220},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25YI27MENCEPZTTGRVU6BQD5V53FNI52/",[190,184],[211,212],{"url":222,"sources":223,"tags":224},"https://nvd.nist.gov/vuln/detail/CVE-2022-27651",[191],[225],"Advisory",{"url":227,"sources":228,"tags":229},"https://github.com/containers/buildah/pull/3855",[191],[196],{"url":231,"sources":232,"tags":233},"https://github.com/containers/buildah/commit/90b3254c7404039c1c786999ac189654228f6e0e",[191],[196],{"url":235,"sources":236,"tags":237},"https://github.com/containers/buildah",[191],[238],"PACKAGE",{"url":240,"sources":241,"tags":242},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/25YI27MENCEPZTTGRVU6BQD5V53FNI52",[191],[196],{"url":244,"sources":245,"tags":246},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2VWH6X6HOFPO6HTESF42HIJZEPXSWVIO",[191],[196],{"url":248,"sources":249,"tags":250},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7NETC7I6RTMMBRJJQVJOJUPDK4W4PQSJ",[191],[196],{"url":252,"sources":253,"tags":254},"https://pkg.go.dev/vuln/GO-2022-0417",[191],[196],[],{"date":257,"score":180,"percentile":258},"2026-06-04",0.3957,[260,264,267,270,273,275,278,281,284,287,290,293,296,298,301,305,308,310,313,315,318,321,324,326,329,332,335,338,341,344,347,350,352,354,357,360,362,365,368,371,374,377,380,383,386,389,392,395,398,401,404,407,410,413,415,418,421,423,427,430,433,437,440,443,446,449,452,455,458,460,463,466,469,472,475,478,481,484,487,490,493,496,499,502,505,508,511,514,517,519],{"date":261,"score":262,"percentile":263},"2025-11-04",0.0012,0.3165,{"date":265,"score":262,"percentile":266},"2025-11-05",0.31627,{"date":268,"score":262,"percentile":269},"2025-11-06",0.31633,{"date":271,"score":262,"percentile":272},"2025-11-07",0.31653,{"date":274,"score":262,"percentile":272},"2025-11-08",{"date":276,"score":262,"percentile":277},"2025-11-09",0.31629,{"date":279,"score":262,"percentile":280},"2025-11-10",0.31581,{"date":282,"score":262,"percentile":283},"2025-11-11",0.31597,{"date":285,"score":262,"percentile":286},"2025-11-12",0.31643,{"date":288,"score":262,"percentile":289},"2025-11-13",0.31663,{"date":291,"score":262,"percentile":292},"2025-11-14",0.31666,{"date":294,"score":262,"percentile":295},"2025-11-15",0.31665,{"date":297,"score":262,"percentile":277},"2025-11-16",{"date":299,"score":262,"percentile":300},"2025-11-17",0.31605,{"date":302,"score":303,"percentile":304},"2025-11-18",0.00331,0.52956,{"date":306,"score":303,"percentile":307},"2025-11-19",0.5297,{"date":309,"score":303,"percentile":304},"2025-11-20",{"date":311,"score":262,"percentile":312},"2025-11-21",0.31645,{"date":314,"score":262,"percentile":263},"2025-11-22",{"date":316,"score":262,"percentile":317},"2025-11-23",0.31623,{"date":319,"score":262,"percentile":320},"2025-11-24",0.31601,{"date":322,"score":262,"percentile":323},"2025-11-25",0.31596,{"date":325,"score":262,"percentile":323},"2025-11-26",{"date":327,"score":262,"percentile":328},"2025-11-27",0.3161,{"date":330,"score":262,"percentile":331},"2025-11-28",0.3159,{"date":333,"score":262,"percentile":334},"2025-11-29",0.31573,{"date":336,"score":262,"percentile":337},"2025-11-30",0.31553,{"date":339,"score":262,"percentile":340},"2025-12-01",0.31632,{"date":342,"score":262,"percentile":343},"2025-12-02",0.31662,{"date":345,"score":262,"percentile":346},"2025-12-03",0.31661,{"date":348,"score":262,"percentile":349},"2025-12-04",0.31559,{"date":351,"score":262,"percentile":323},"2025-12-05",{"date":353,"score":262,"percentile":283},"2025-12-06",{"date":355,"score":262,"percentile":356},"2025-12-07",0.31569,{"date":358,"score":262,"percentile":359},"2025-12-08",0.31582,{"date":361,"score":262,"percentile":269},"2025-12-09",{"date":363,"score":262,"percentile":364},"2025-12-10",0.31691,{"date":366,"score":262,"percentile":367},"2025-12-11",0.31726,{"date":369,"score":262,"percentile":370},"2025-12-12",0.31761,{"date":372,"score":262,"percentile":373},"2025-12-13",0.31748,{"date":375,"score":262,"percentile":376},"2025-12-14",0.31722,{"date":378,"score":262,"percentile":379},"2025-12-15",0.31671,{"date":381,"score":262,"percentile":382},"2025-12-16",0.31689,{"date":384,"score":262,"percentile":385},"2025-12-17",0.31741,{"date":387,"score":262,"percentile":388},"2025-12-18",0.3179,{"date":390,"score":262,"percentile":391},"2025-12-19",0.31816,{"date":393,"score":262,"percentile":394},"2025-12-20",0.31798,{"date":396,"score":262,"percentile":397},"2025-12-21",0.31742,{"date":399,"score":262,"percentile":400},"2025-12-22",0.31711,{"date":402,"score":262,"percentile":403},"2025-12-23",0.31692,{"date":405,"score":262,"percentile":406},"2025-12-24",0.31686,{"date":408,"score":262,"percentile":409},"2025-12-25",0.3176,{"date":411,"score":262,"percentile":412},"2025-12-26",0.31746,{"date":414,"score":262,"percentile":409},"2025-12-27",{"date":416,"score":262,"percentile":417},"2025-12-28",0.31682,{"date":419,"score":262,"percentile":420},"2025-12-29",0.31648,{"date":422,"score":262,"percentile":286},"2025-12-30",{"date":424,"score":425,"percentile":426},"2025-12-31",0.00126,0.32641,{"date":428,"score":425,"percentile":429},"2026-01-01",0.32787,{"date":431,"score":425,"percentile":432},"2026-01-02",0.32776,{"date":434,"score":435,"percentile":436},"2026-01-03",0.00165,0.38148,{"date":438,"score":435,"percentile":439},"2026-01-04",0.37986,{"date":441,"score":435,"percentile":442},"2026-01-05",0.37963,{"date":444,"score":435,"percentile":445},"2026-01-06",0.3797,{"date":447,"score":435,"percentile":448},"2026-01-07",0.37994,{"date":450,"score":435,"percentile":451},"2026-01-08",0.38021,{"date":453,"score":435,"percentile":454},"2026-01-09",0.38015,{"date":456,"score":435,"percentile":457},"2026-01-10",0.38019,{"date":459,"score":435,"percentile":448},"2026-01-11",{"date":461,"score":435,"percentile":462},"2026-01-12",0.37946,{"date":464,"score":435,"percentile":465},"2026-01-13",0.37925,{"date":467,"score":435,"percentile":468},"2026-01-14",0.37979,{"date":470,"score":435,"percentile":471},"2026-01-15",0.37968,{"date":473,"score":435,"percentile":474},"2026-01-16",0.37988,{"date":476,"score":435,"percentile":477},"2026-01-17",0.37954,{"date":479,"score":435,"percentile":480},"2026-01-18",0.37902,{"date":482,"score":435,"percentile":483},"2026-01-19",0.37868,{"date":485,"score":435,"percentile":486},"2026-01-20",0.37848,{"date":488,"score":435,"percentile":489},"2026-01-21",0.37826,{"date":491,"score":435,"percentile":492},"2026-01-22",0.37807,{"date":494,"score":435,"percentile":495},"2026-01-23",0.37867,{"date":497,"score":435,"percentile":498},"2026-01-24",0.37874,{"date":500,"score":435,"percentile":501},"2026-01-25",0.37818,{"date":503,"score":435,"percentile":504},"2026-01-26",0.3775,{"date":506,"score":435,"percentile":507},"2026-01-27",0.37746,{"date":509,"score":435,"percentile":510},"2026-01-28",0.37734,{"date":512,"score":435,"percentile":513},"2026-01-29",0.3771,{"date":515,"score":435,"percentile":516},"2026-01-30",0.37706,{"date":518,"score":435,"percentile":516},"2026-01-31",{"date":520,"score":435,"percentile":521},"2026-02-01",0.3781,[523,531],{"source":184,"cvss_v2_0":524,"cvss_v3_0":9,"cvss_v3_1":527,"cvss_v4_0":9},{"baseScore":525,"baseSeverity":9,"vectorString":526,"impactScore":525,"exploitabilityScore":182},4.9,"AV:N/AC:M/Au:S/C:P/I:P/A:N",{"baseScore":182,"baseSeverity":528,"vectorString":185,"impactScore":529,"exploitabilityScore":530},"MEDIUM",8.7,4.1,{"source":191,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":532,"cvss_v4_0":9},{"baseScore":182,"baseSeverity":9,"vectorString":185,"impactScore":529,"exploitabilityScore":530},[534,545,556,565],{"ecosystem":9,"name":535,"vendor":536,"product":535,"cpe_part":537,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":538},"buildah","buildah_project","a",[539],{"version":540,"is_range":541,"range_type":542,"version_start":9,"version_start_type":9,"version_end":543,"version_end_type":544,"fixed_in":9},"lt1.25.0",true,"cpe","1.25.0","excluding",{"ecosystem":9,"name":546,"vendor":547,"product":546,"cpe_part":548,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":549},"fedora","fedoraproject","o",[550,552,554],{"version":551,"is_range":178,"range_type":542,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"34",{"version":553,"is_range":178,"range_type":542,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"35",{"version":555,"is_range":178,"range_type":542,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"36",{"ecosystem":557,"name":558,"vendor":559,"product":535,"cpe_part":9,"purl_type":560,"purl_namespace":559,"purl_name":535,"source":9,"versions":561},"Go","github.com/containers/buildah","github.com/containers","golang",[562],{"version":563,"is_range":541,"range_type":564,"version_start":9,"version_start_type":9,"version_end":543,"version_end_type":544,"fixed_in":9},"lt1_25_0","semver",{"ecosystem":9,"name":566,"vendor":567,"product":568,"cpe_part":548,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":569},"enterprise linux","redhat","enterprise_linux",[570,572],{"version":571,"is_range":178,"range_type":542,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0",{"version":573,"is_range":178,"range_type":542,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0"]