CVE-2020-10696
31.03.2020, 22:15
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
| Vendor | Product | Version |
|---|---|---|
| buildah_project | buildah | 𝑥 < 1.14.5 |
| redhat | openshift_container_platform | 3.11 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References