pkg:Go/github.com/containers/buildah

16 total CVEsHIGH8MEDIUM8

✅ Check your installed version

All known vulnerabilities

  • HIGH8.8CVE-2020-10696Path Traversal in Buildah
    from 0, < 1.14.4
  • HIGH8.8CVE-2020-10696Path Traversal in Buildah
    from 0, < 1.14.4
  • HIGH8.6CVE-2024-11218Buildah allows build breakout using malicious Containerfiles and concurrent builds
    from 0, < 1.33.12, >= 1.35.0, < 1.35.5, >= 1.37.0, < 1.37.6, >= 1.38.0, < 1.38.1
  • HIGH8.6CVE-2024-11218Buildah allows build breakout using malicious Containerfiles and concurrent builds
    >= 1.38.0, < 1.38.1
  • HIGH8.6CVE-2024-1753Podman affected by CVE-2024-1753 container escape at build time
    >= 1.35.0, < 1.35.1
  • HIGH8.6CVE-2024-1753Podman affected by CVE-2024-1753 container escape at build time
    from 0, < 1.35.1
  • HIGH7.1CVE-2022-2990Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification
    from 0, < 1.27.1
  • HIGH7.1CVE-2022-2990Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification
    from 0, < 1.27.1
  • MEDIUM6.8CVE-2022-27651Non-empty default inheritable capabilities for linux container in Buildah
    from 0, < 1.25.0
  • MEDIUM6.8CVE-2022-27651Non-empty default inheritable capabilities for linux container in Buildah
    from 0, < 1.25.0
  • MEDIUM5.5CVE-2021-3602Buildah processes using chroot isolation may leak environment values to intermediate processes
    from 0, < 1.22.0
  • MEDIUM5.5CVE-2021-3602Buildah processes using chroot isolation may leak environment values to intermediate processes
    from 0, < 1.16.8
  • MEDIUM4.7CVE-2024-9407Improper Input Validation in Buildah and Podman
    from 0, < 1.37.4
  • MEDIUM4.7CVE-2024-9407Improper Input Validation in Buildah and Podman
    from 0, < 1.37.4
  • MEDIUM4.4CVE-2024-9675Buildah allows arbitrary directory mount
    from 0, < 1.37.1
  • MEDIUM4.4CVE-2024-9675Buildah allows arbitrary directory mount
    from 0, < 1.38.0