Описание
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
A path traversal flaw was found in Buildah. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Отчет
While OpenShift Container Platform does include the vulnerable buildah code, it doesn't make use of the vulnerable function. Podman is also included in OpenShift Container Platform, but it isn't used to perform a build, so it has been given a low impact rating. OpenShift Container Platform 3.11 now used podman from the RHEL Extra repository, and not the podman package shipped in the OpenShift 3.11 RPM repository. This issue is fixed in podman in RHEL Extras so we won't fix the podman package shipped in the OpenShift 3.11 RPM repository.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Fix deferred | ||
Red Hat OpenShift Container Platform 3.11 | podman | Will not fix | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-docker-builder | Fix deferred | ||
Red Hat Enterprise Linux 7 Extras | buildah | Fixed | RHSA-2020:2116 | 12.05.2020 |
Red Hat Enterprise Linux 7 Extras | podman | Fixed | RHSA-2020:2117 | 12.05.2020 |
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2020:1926 | 28.04.2020 |
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2020:1931 | 28.04.2020 |
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2020:1932 | 28.04.2020 |
Red Hat OpenShift Container Platform 4.1 | podman | Fixed | RHSA-2020:1449 | 22.04.2020 |
Red Hat OpenShift Container Platform 4.2 | podman | Fixed | RHSA-2020:1401 | 14.04.2020 |
Показывать по
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
A path traversal flaw was found in Buildah in versions before 1.14.5. ...
8.8 High
CVSS3