Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-10696

Опубликовано: 31 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9.3
CVSS3: 8.8

Описание

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

not-affected

1.15.2-1ubuntu2
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

1.11.6-2

Показывать по

EPSS

Процентиль: 71%
0.00677
Низкий

9.3 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
nvd
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
debian
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. ...

rocky
около 5 лет назад

Important: container-tools:rhel8 security update

rocky
около 5 лет назад

Important: container-tools:2.0 security update

EPSS

Процентиль: 71%
0.00677
Низкий

9.3 Critical

CVSS2

8.8 High

CVSS3