Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4123

Опубликовано: 22 нояб. 2022
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

Отчет

These bugs come about when "podman --remote build -t test1 -f /tmp/Dockerfile> emptydir" is run, thus affecting buildah, but the bug itself needs to be fixed in podman, and ported to Buildah.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7buildahOut of support scope
Red Hat Enterprise Linux 7podmanOut of support scope
Red Hat Enterprise Linux 8container-tools:3.0/podmanNot affected
Red Hat Enterprise Linux 8container-tools:4.0/podmanFix deferred
Red Hat Enterprise Linux 8container-tools:rhel8/podmanFix deferred
Red Hat Enterprise Linux 9podmanFix deferred
Red Hat OpenShift Container Platform 3.11podmanUnder investigation
Red Hat OpenShift Container Platform 4buildahAffected
Red Hat OpenShift Container Platform 4podmanUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-23

EPSS

Процентиль: 12%
0.00041
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.3
nvd
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.3
msrc
4 месяца назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.3
debian
около 3 лет назад

A flaw was found in Buildah. The local path and the lowest subdirector ...

CVSS3: 3.3
github
около 3 лет назад

Buildah (as part of Podman) vulnerable to Path Traversal

EPSS

Процентиль: 12%
0.00041
Низкий

3.1 Low

CVSS3