A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
References
Configurations
No configuration.
History
21 Nov 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
13 Nov 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Nov 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Nov 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
06 Nov 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
06 Nov 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
05 Nov 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 Oct 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Oct 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Oct 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Oct 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
10 Oct 2024, 12:51
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-09 15:15
Updated : 2024-11-21 19:15
NVD link : CVE-2024-9675
Mitre link : CVE-2024-9675
CVE.ORG link : CVE-2024-9675
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')