CVE-2020-10696 PUBLISHED CVSS 8.8 HIGH

Reported by redhat · Published March 31, 2020

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

Risk Scores

CVSS v3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatbuildahFixed in buildah-1.14.5
Red HatbuildahFixed in buildah-1.14.5, Fixed in buildah-1.14.5, Fixed in buildah-1.14.5
chainguardbuildah*, *
github.comcontainers/buildah/imagebuildah0, 0, 0
wolfibuildah*, *, *
github.comcontainers/buildah0, 0, 0

Timeline

References

Open in Interactive Console →