Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx8w-mjvm-hvpc

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Path Traversal in Buildah

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

Specific Go Packages Affected

github.com/containers/buildah/imagebuildah

Пакеты

Наименование

github.com/containers/buildah

go
Затронутые версииВерсия исправления

< 1.14.4

1.14.4

EPSS

Процентиль: 71%
0.00677
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
redhat
больше 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
nvd
больше 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
debian
больше 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. ...

rocky
около 5 лет назад

Important: container-tools:rhel8 security update

EPSS

Процентиль: 71%
0.00677
Низкий

8.8 High

CVSS3

Дефекты

CWE-22