PT-2020-2769 · Red Hat+5 · Buildah+6

Published

2020-03-31

·

Updated

2024-12-18

·

CVE-2020-10696

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Buildah versions prior to 1.14.5
Description A path traversal flaw was found in Buildah. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. The issue exists due to incorrect restriction of the path name to a directory with limited access, which can be exploited by a remote attacker to create a malicious container image and replace arbitrary files in the user's system.
Recommendations For versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of Buildah to minimize the risk of exploitation. Avoid using Buildah to build container images from untrusted sources until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALSA-2020:1926
ALSA-2020:1931
ALSA-2020:1932
ALSA-2020_1926
ALSA-2020_1931
ALSA-2020_1932
ALT-PU-2020-1656
ALT-PU-2020-2856
BDU:2020-02861
CESA-2020_1926
CESA-2020_1931
CESA-2020_1932
CVE-2020-10696
ELSA-2020-1926
ELSA-2020-1931
ELSA-2020-1932
GHSA-FX8W-MJVM-HVPC
GO-2022-0828
OPENSUSE-SU-2020:2106-1
OPENSUSE-SU-2020_2106-1
OPENSUSE-SU-2021:0310-1
OPENSUSE-SU-2021_0310-1
OPENSUSE-SU-2022:0770-1
OPENSUSE-SU-2022_0770-1
OPENSUSE-SU-2022_3655-1
OPENSUSE-SU-2022_3766-1
OPENSUSE-SU-2022_4349-1
OPENSUSE-SU-2022_4350-1
OPENSUSE-SU-2024:10666-1
OPENSUSE-SU-2024:14599-1
RHSA-2020:1396
RHSA-2020:1401
RHSA-2020:1449
RHSA-2020:1926
RHSA-2020:1931
RHSA-2020:1932
RHSA-2020:2116
RHSA-2020:2117
RHSA-2020_1926
RHSA-2020_1931
RHSA-2020_1932
RLSA-2020:1926
RLSA-2020:1931
RLSA-2020:1932
RLSA-2020_1926
RLSA-2020_1931
RLSA-2020_1932
SUSE-SU-2020:3423-1
SUSE-SU-2020_3423-1
SUSE-SU-2022:0770-1
SUSE-SU-2022:3480-1
SUSE-SU-2022:3655-1
SUSE-SU-2022:3766-1
SUSE-SU-2022:4349-1
SUSE-SU-2022:4350-1
SUSE-SU-2022_0770-1
SUSE-SU-2022_3480-1
SUSE-SU-2022_3655-1
SUSE-SU-2022_3766-1
SUSE-SU-2022_4349-1
SUSE-SU-2022_4350-1

Affected Products

Alt Linux
Almalinux
Buildah
Centos
Red Hat
Rocky Linux
Suse