Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rprg-4v7q-87v7

Опубликовано: 08 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

Buildah (as part of Podman) vulnerable to Path Traversal

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

Пакеты

Наименование

github.com/containers/podman/v4

go
Затронутые версииВерсия исправления

>= 4.1.0-rc1, <= 4.4.1

Отсутствует

EPSS

Процентиль: 12%
0.00041
Низкий

3.3 Low

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.1
redhat
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.3
nvd
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.3
msrc
4 месяца назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.3
debian
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirector ...

EPSS

Процентиль: 12%
0.00041
Низкий

3.3 Low

CVSS3

Дефекты

CWE-23