CVE-2020-10696
HIGH8.8EPSS 0.26%Path Traversal in Buildah
發布日:2021/5/18修改日:2026/2/4
描述
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. ### Specific Go Packages Affected github.com/containers/buildah/imagebuildah
受影響套件(3)
- Debian/golang-github-containers-buildahfrom 0, < 1.11.6-2
- Go/github.com/containers/buildahfrom 0, < 1.14.4
- Go/github.com/containers/buildahfrom 0, < 1.14.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(9)
- ADVISORYhttps://github.com/advisories/GHSA-fx8w-mjvm-hvpc
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-10696
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-10696
- PATCHhttps://github.com/containers/buildah
- WEBhttps://access.redhat.com/security/cve/cve-2020-10696
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1817651
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10696
- WEBhttps://github.com/containers/buildah/pull/2245
- WEBhttps://pkg.go.dev/vuln/GO-2022-0828