Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27534

Опубликовано: 31 дек. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.

A flaw was found in moby. Moby buildkit calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-cliNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-cli-artifactsNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-hyperkube-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-hypershiftNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-kube-proxyNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-testsNot affected
Red Hat OpenShift Container Platform 4openshift-enterprise-node-containerNot affected
Red Hat OpenShift Container Platform 4source-to-image-containerNot affected
Red Hat OpenShift Container Platform 4windows-machine-config-operatorNot affected
Red Hat Quay 3quay-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1921154moby/buildkit: calls os.OpenFile with a potentially unsafe qemu-check temporary pathname

EPSS

Процентиль: 73%
0.0077
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.

CVSS3: 5.3
nvd
около 5 лет назад

util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.

CVSS3: 5.3
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 5 лет назад

util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 c ...

CVSS3: 5.3
github
около 2 лет назад

Path Traversal in Moby builder

EPSS

Процентиль: 73%
0.0077
Низкий

5.3 Medium

CVSS3