Описание
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a RUN
instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Developer Tools and Services | ocp-tools-4/jenkins-agent-base-rhel8 | Will not fix | ||
OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Will not fix | ||
Red Hat Enterprise Linux 10 | buildah | Not affected | ||
Red Hat Enterprise Linux 10 | podman | Not affected | ||
Red Hat Enterprise Linux 7 | skopeo | Out of support scope | ||
Red Hat Enterprise Linux 9 | conmon | Not affected | ||
Red Hat OpenShift Container Platform 4 | buildah | Not affected | ||
Red Hat OpenShift Container Platform 4 | conmon | Affected | ||
Red Hat OpenShift Container Platform 4 | cri-o | Not affected | ||
Red Hat Quay 3 | quay/quay-builder-rhel8 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
A vulnerability was found in Buildah. Cache mounts do not properly val ...
EPSS
7.8 High
CVSS3