Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49p4-px3h-rq49

Опубликовано: 22 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

Impact

When processing a build contexts or add/copy instructions, a malicious server serving a Git repository or a tar archive file can cause files outside of the build context directory to be included in the build context or copied into the build.

Patches

Fixed in Buildah 1.44 and 1.43.2.

Пакеты

Наименование

github.com/containers/buildah

go
Затронутые версииВерсия исправления

>= 1.38.1, < 1.43.2

1.43.2

6.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

ubuntu
около 2 месяцев назад

[Unknown description]

debian

Описание отсутствует

6.3 Medium

CVSS3

Дефекты

CWE-22