​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-2x82-jh2m-c6cj

Published

Last updated

https://images.chainguard.dev/security/CGA-2x82-jh2m-c6cj
Package

buildah

Latest Update
Not affected
Aliases
  • CVE-2020-10696
  • GHSA-fx8w-mjvm-hvpc

Severity

8.8

High

CVSS V3

Summary

Path Traversal in Buildah

Description

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

Specific Go Packages Affected

github.com/containers/buildah/imagebuildah

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images