A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1069 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. |
Github GHSA |
GHSA-fx8w-mjvm-hvpc | Path Traversal in Buildah |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T11:06:11.148Z
Reserved: 2020-03-20T00:00:00.000Z
Link: CVE-2020-10696
No data.
Status : Modified
Published: 2020-03-31T22:15:14.667
Modified: 2024-11-21T04:55:52.387
Link: CVE-2020-10696
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA