CVE-2020-10696
Vulnerability Summary
Timeline
Description
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 2.67%• Percentile: 85%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- chainguard•buildah
< 0
- wolfi•buildah
< 0
- buildah_project•buildah
< 1.14.5
- debian•golang-github-containers-buildah
< 1.11.6-2 | < 1.11.6-2 | < 1.11.6-2 | < 1.11.6-2
- github.com/containers•buildah
< 1.14.4
- red hat•buildah
Fixed in buildah-1.14.5
- redhat•enterprise_linux
7.0 | 8.0
- redhat•openshift_container_platform
3.11
- redhat•afterburn
< 0:4.1.1-3.rhaos4.2.el8
- redhat•afterburn-debuginfo
< 0:4.1.1-3.rhaos4.2.el8
- redhat•ansible-asb-modules
< 0:0.4.1-1.el7
- redhat•ansible-kubernetes-modules
< 0:0.4.0-8.el7
- redhat•ansible-runner
< 0:1.3.4-2.el7ar
- redhat•ansible-runner-http
< 0:1.0-1.el7ar
- redhat•apb
< 0:2.0.3-2.el7
- redhat•apb-base-scripts
< 0:1.4.2-1.el7
- redhat•apb-container-scripts
< 0:2.0.3-2.el7
- redhat•apb-devel
< 0:2.0.3-2.el7
- redhat•atomic-enterprise-service-catalog
< 1:4.4.0-202004260017.git.1.6957195.el7
- redhat•atomic-enterprise-service-catalog-svcat
< 1:4.4.0-202004260017.git.1.6957195.el7
- redhat•atomic-openshift-service-idler
< 0:4.4.0-202004260017.git.1.e04c72f.el7
- redhat•buildah
< 0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca | < 0:1.11.6-7.module+el8.2.0+6369+1f4293b4 | < 0:1.11.6-8.module+el8.2.0+6368+cf16aa14 | < 0:1.11.6-6.rhaos4.4.el8
- redhat•buildah-debuginfo
< 0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca | < 0:1.11.6-7.module+el8.2.0+6369+1f4293b4 | < 0:1.11.6-8.module+el8.2.0+6368+cf16aa14 | < 0:1.11.6-6.rhaos4.4.el8
- redhat•buildah-debugsource
< 0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca | < 0:1.11.6-7.module+el8.2.0+6369+1f4293b4 | < 0:1.11.6-8.module+el8.2.0+6368+cf16aa14 | < 0:1.11.6-6.rhaos4.4.el8
- redhat•buildah-tests
< 0:1.11.6-7.module+el8.2.0+6369+1f4293b4 | < 0:1.11.6-8.module+el8.2.0+6368+cf16aa14 | < 0:1.11.6-6.rhaos4.4.el8
- redhat•buildah-tests-debuginfo
< 0:1.11.6-7.module+el8.2.0+6369+1f4293b4 | < 0:1.11.6-8.module+el8.2.0+6368+cf16aa14 | < 0:1.11.6-6.rhaos4.4.el8
- redhat•cockpit-podman
< 0:11-1.module+el8.2.0+6369+1f4293b4 | < 0:12-1.module+el8.2.0+6368+cf16aa14
- redhat•conmon
< 2:2.0.6-1.module+el8.2.0+6369+1f4293b4 | < 2:2.0.6-1.module+el8.2.0+6368+cf16aa14 | < 2:2.0.15-1.rhaos4.4.el7 | < 2:2.0.15-1.rhaos4.4.el8
- redhat•console-login-helper-messages
< 0:0.16-1.rhaos4.2.el8
- redhat•console-login-helper-messages-issuegen
< 0:0.16-1.rhaos4.2.el8
- redhat•console-login-helper-messages-profile
< 0:0.16-1.rhaos4.2.el8
- redhat•container-selinux
< 2:2.124.0-1.gitf958d0c.module+el8.2.0+6370+6fb6c8ca | < 2:2.124.0-1.module+el8.2.0+6369+1f4293b4 | < 2:2.124.0-1.module+el8.2.0+6368+cf16aa14
- redhat•containernetworking-plugins
< 0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca | < 0:0.8.3-4.module+el8.2.0+6369+1f4293b4 | < 0:0.8.3-5.module+el8.2.0+6368+cf16aa14 | < 0:0.8.2-3.el7 | < 0:0.8.2-2.el8
- redhat•containernetworking-plugins-debuginfo
< 0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca | < 0:0.8.3-4.module+el8.2.0+6369+1f4293b4 | < 0:0.8.3-5.module+el8.2.0+6368+cf16aa14 | < 0:0.8.2-3.el7 | < 0:0.8.2-2.el8
- redhat•containernetworking-plugins-debugsource
< 0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca | < 0:0.8.3-4.module+el8.2.0+6369+1f4293b4 | < 0:0.8.3-5.module+el8.2.0+6368+cf16aa14 | < 0:0.8.2-2.el8
- redhat•containers-common
< 1:0.1.32-4.git1715c90.module+el8.2.0+6370+6fb6c8ca | < 1:0.1.40-9.module+el8.2.0+6373+4950d421 | < 1:0.1.40-11.module+el8.2.0+6374+67f43e89 | < 1:0.1.40-1.rhaos4.3.el7 | < 1:0.1.40-6.rhaos4.4.el8
- redhat•coreos-installer
< 0:0-2.rhaos4.4.gite5aa5dc.el8
- redhat•coreos-installer-dracut
< 0:0-2.rhaos4.4.gite5aa5dc.el8
- redhat•cri-tools
< 0:1.17.0-1.el7 | < 0:1.17.0-2.el8
- redhat•cri-tools-debuginfo
< 0:1.17.0-1.el7 | < 0:1.17.0-2.el8
- redhat•cri-tools-debugsource
< 0:1.17.0-2.el8
- redhat•crit
< 0:3.12-9.module+el8.2.0+6370+6fb6c8ca | < 0:3.12-9.module+el8.2.0+6369+1f4293b4 | < 0:3.12-9.module+el8.2.0+6368+cf16aa14
- redhat•criu
< 0:3.12-9.module+el8.2.0+6370+6fb6c8ca | < 0:3.12-9.module+el8.2.0+6369+1f4293b4 | < 0:3.12-9.module+el8.2.0+6368+cf16aa14
- redhat•criu-debuginfo
< 0:3.12-9.module+el8.2.0+6370+6fb6c8ca | < 0:3.12-9.module+el8.2.0+6369+1f4293b4 | < 0:3.12-9.module+el8.2.0+6368+cf16aa14
- redhat•criu-debugsource
< 0:3.12-9.module+el8.2.0+6370+6fb6c8ca | < 0:3.12-9.module+el8.2.0+6369+1f4293b4 | < 0:3.12-9.module+el8.2.0+6368+cf16aa14
- redhat•dracut
< 0:049-70.git20200228.el8
- redhat•dracut-caps
< 0:049-70.git20200228.el8
- redhat•dracut-config-generic
< 0:049-70.git20200228.el8
- redhat•dracut-config-rescue
< 0:049-70.git20200228.el8
- redhat•dracut-debuginfo
< 0:049-70.git20200228.el8
Showing first 50 affected entries in server-rendered view.
References (29)
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10696
- https://github.com/containers/buildah/pull/2245
- https://access.redhat.com/security/cve/cve-2020-10696
- https://nvd.nist.gov/vuln/detail/CVE-2020-10696
- https://bugzilla.redhat.com/show_bug.cgi?id=1817651
- https://github.com/containers/buildah
- https://pkg.go.dev/vuln/GO-2022-0828
- https://github.com/advisories/GHSA-fx8w-mjvm-hvpc
- https://access.redhat.com/errata/RHBA-2020:0582
- https://bugzilla.redhat.com/show_bug.cgi?id=1767877
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhba-2020_0582.json
- https://access.redhat.com/security/cve/CVE-2020-10696
- https://www.cve.org/CVERecord?id=CVE-2020-10696
- https://access.redhat.com/errata/RHSA-2020:1401
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1401.json
- https://access.redhat.com/errata/RHSA-2020:1449
- https://access.redhat.com/security/updates/classification/#low
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1449.json
- https://access.redhat.com/errata/RHSA-2020:1926
- https://bugzilla.redhat.com/show_bug.cgi?id=1776313
- https://bugzilla.redhat.com/show_bug.cgi?id=1813776
- https://bugzilla.redhat.com/show_bug.cgi?id=1816541
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1926.json
- https://access.redhat.com/errata/RHSA-2020:1931
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1931.json
- https://access.redhat.com/errata/RHSA-2020:1932
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1932.json
- https://security-tracker.debian.org/tracker/CVE-2020-10696