Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10696

Опубликовано: 26 мар. 2020
Источник: redhat
CVSS3: 8.8

Описание

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

A path traversal flaw was found in Buildah. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

Отчет

While OpenShift Container Platform does include the vulnerable buildah code, it doesn't make use of the vulnerable function. Podman is also included in OpenShift Container Platform, but it isn't used to perform a build, so it has been given a low impact rating. OpenShift Container Platform 3.11 now used podman from the RHEL Extra repository, and not the podman package shipped in the OpenShift 3.11 RPM repository. This issue is fixed in podman in RHEL Extras so we won't fix the podman package shipped in the OpenShift 3.11 RPM repository.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11atomic-openshiftFix deferred
Red Hat OpenShift Container Platform 3.11podmanWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-docker-builderFix deferred
Red Hat Enterprise Linux 7 ExtrasbuildahFixedRHSA-2020:211612.05.2020
Red Hat Enterprise Linux 7 ExtraspodmanFixedRHSA-2020:211712.05.2020
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2020:192628.04.2020
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2020:193128.04.2020
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2020:193228.04.2020
Red Hat OpenShift Container Platform 4.1podmanFixedRHSA-2020:144922.04.2020
Red Hat OpenShift Container Platform 4.2podmanFixedRHSA-2020:140114.04.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1817651buildah: Crafted input tar file may lead to local file overwrite during image build process

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
nvd
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
debian
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. ...

rocky
около 5 лет назад

Important: container-tools:rhel8 security update

rocky
около 5 лет назад

Important: container-tools:2.0 security update

8.8 High

CVSS3