CVE-2024-9675

Aliases:GHSA-586p-749j-fhwpGO-2024-3186
Analyzed
Published: 09 Oct 2024, 14:32
Last modified:18 Mar 2026, 08:03

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.14% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Oct 2024, 14:32
Published
Vulnerability first disclosed
18 Mar 2026, 08:03
Last Modified
Vulnerability information updated

Description

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS Metrics

  • v4.0MEDIUMScore: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.14% Percentile: 34%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • buildah_projectbuildah

    na

  • github.com/containersbuildah

    < 1.38.0 | < 1.37.1

  • redhatenterprise_linux

    8.0 | 9.0

  • redhatenterprise_linux_eus

    8.8 | 9.0 | 9.2 | 9.4

  • redhatenterprise_linux_for_arm_64

    8.0_aarch64 | 9.0_aarch64

  • redhatenterprise_linux_for_arm_64_eus

    8.8_aarch64 | 9.0_aarch64 | 9.2_aarch64 | 9.4_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    8.0_s390x | 9.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    8.8_s390x | 9.0_s390x | 9.2_s390x | 9.4_s390x

  • redhatenterprise_linux_for_power_little_endian

    8.0_ppc64le | 9.0_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    8.8_ppc64le | 9.0_ppc64le | 9.2_ppc64le | 9.4_ppc64le

  • redhatenterprise_linux_server_aus

    8.6 | 9.2 | 9.4

  • redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

    8.6_ppc64le | 8.8_ppc64le | 9.0_ppc64le | 9.2_ppc64le | 9.4_ppc64le

  • redhatenterprise_linux_server_tus

    8.6 | 8.8

  • redhatenterprise_linux_update_services_for_sap_solutions

    8.6 | 8.8 | 9.0 | 9.2 | 9.4

  • redhatopenshift_container_platform

    4.13 | 4.14 | 4.15 | 4.16 | 4.17

References (30)