CVE-2020-10696
31.03.2020, 22:15
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Vendor | Product | Version |
---|---|---|
buildah_project | buildah | 𝑥 < 1.14.5 |
redhat | openshift_container_platform | 3.11 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References