Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-586p-749j-fhwp

Опубликовано: 09 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.4

Описание

Buildah allows arbitrary directory mount

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a RUN instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

Пакеты

Наименование

github.com/containers/buildah

go
Затронутые версииВерсия исправления

< 1.38.0

1.38.0

EPSS

Процентиль: 21%
0.00066
Низкий

5.3 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS3: 7.8
redhat
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS3: 7.8
nvd
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS3: 7.8
debian
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly val ...

suse-cvrf
8 месяцев назад

Security update for buildah

EPSS

Процентиль: 21%
0.00066
Низкий

5.3 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-22