CVE-2020-10696

Aliases:GHSA-fx8w-mjvm-hvpcGO-2022-0828
Modified
Published: 31 Mar 2020, 21:01
Last modified:04 Aug 2024, 11:06

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
0.26% LOW
0% probability -0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

31 Mar 2020, 21:01
Published
Vulnerability first disclosed
04 Aug 2024, 11:06
Last Modified
Vulnerability information updated

Description

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.26% Percentile: 49%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • buildah_projectbuildah

    < 1.14.5

  • github.com/containersbuildah

    < 1.14.4

  • red hatbuildah

    Fixed in buildah-1.14.5

  • redhatenterprise_linux

    7.0 | 8.0

  • redhatopenshift_container_platform

    3.11

References (8)