Описание
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
Ссылки
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.9 Critical
CVSS3
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
The build package before 20171128 did not check directory names during ...
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
EPSS
9.9 Critical
CVSS3
5.3 Medium
CVSS3
5 Medium
CVSS2