CVE-2024-9675
Vulnerability Summary
Timeline
Description
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
CVSS Metrics
- v4.0•MEDIUM•Score: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.1•MEDIUM•Score: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Trends
Current EPSS score: 0.39%• Percentile: 33%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- chainguard•buildah
< 1.39.0-r2
- chainguard•prometheus-podman-exporter
< 1.13.3-r2
- wolfi•buildah
< 1.39.0-r2
- buildah_project•buildah
na
- debian•golang-github-containers-buildah
all | all | < 1.37.4+ds1-1 | < 1.37.4+ds1-1
- github.com/containers•buildah
< 1.37.1 | < 1.38.0
- redhat•enterprise_linux
8.0 | 9.0
- redhat•enterprise_linux_eus
8.8 | 9.0 | 9.2 | 9.4
- redhat•enterprise_linux_for_arm_64
8.0_aarch64 | 9.0_aarch64
- redhat•enterprise_linux_for_arm_64_eus
8.8_aarch64 | 9.0_aarch64 | 9.2_aarch64 | 9.4_aarch64
- redhat•enterprise_linux_for_ibm_z_systems
8.0_s390x | 9.0_s390x
- redhat•enterprise_linux_for_ibm_z_systems_eus
8.8_s390x | 9.0_s390x | 9.2_s390x | 9.4_s390x
- redhat•enterprise_linux_for_power_little_endian
8.0_ppc64le | 9.0_ppc64le
- redhat•enterprise_linux_for_power_little_endian_eus
8.8_ppc64le | 9.0_ppc64le | 9.2_ppc64le | 9.4_ppc64le
- redhat•enterprise_linux_server_aus
8.6 | 9.2 | 9.4
- redhat•enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
8.6_ppc64le | 8.8_ppc64le | 9.0_ppc64le | 9.2_ppc64le | 9.4_ppc64le
- redhat•enterprise_linux_server_tus
8.6 | 8.8
- redhat•enterprise_linux_update_services_for_sap_solutions
8.6 | 8.8 | 9.0 | 9.2 | 9.4
- redhat•openshift_container_platform
4.13 | 4.14 | 4.15 | 4.16 | 4.17
- redhat•aardvark-dns
< 2:1.0.1-40.module+el8.6.0+22399+813f5137 | < 2:1.5.0-2.module+el8.8.0+22334+bb93e398
- redhat•buildah
< 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2
- redhat•buildah-debuginfo
< 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2
- redhat•buildah-debugsource
< 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2
- redhat•buildah-tests
< 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2
- redhat•buildah-tests-debuginfo
< 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2
- redhat•cockpit-podman
< 0:49.1-1.module+el8.6.0+22399+813f5137 | < 0:63.1-1.module+el8.8.0+22334+bb93e398
- redhat•conmon
< 2:2.1.4-1.module+el8.6.0+22399+813f5137 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398
- redhat•conmon-debuginfo
< 2:2.1.4-1.module+el8.6.0+22399+813f5137 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398
- redhat•conmon-debugsource
< 2:2.1.4-1.module+el8.6.0+22399+813f5137 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398
- redhat•container-selinux
< 2:2.189.0-1.module+el8.6.0+22399+813f5137 | < 2:2.229.0-1.module+el8.8.0+22334+bb93e398
- redhat•containernetworking-plugins
< 1:1.1.1-5.module+el8.6.0+22399+813f5137 | < 1:1.2.0-2.module+el8.8.0+22334+bb93e398
- redhat•containernetworking-plugins-debuginfo
< 1:1.1.1-5.module+el8.6.0+22399+813f5137 | < 1:1.2.0-2.module+el8.8.0+22334+bb93e398
- redhat•containernetworking-plugins-debugsource
< 1:1.1.1-5.module+el8.6.0+22399+813f5137 | < 1:1.2.0-2.module+el8.8.0+22334+bb93e398
- redhat•containers-common
< 2:1-40.module+el8.6.0+22399+813f5137 | < 2:1-67.module+el8.8.0+22334+bb93e398
- redhat•crit
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-debuginfo
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-debugsource
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-devel
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-libs
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-libs-debuginfo
< 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•crun
< 0:1.5-1.module+el8.6.0+22399+813f5137 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398
- redhat•crun-debuginfo
< 0:1.5-1.module+el8.6.0+22399+813f5137 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398
- redhat•crun-debugsource
< 0:1.5-1.module+el8.6.0+22399+813f5137 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398
- redhat•fuse-overlayfs
< 0:1.9-1.module+el8.6.0+22399+813f5137 | < 0:1.11-1.module+el8.8.0+22334+bb93e398
- redhat•fuse-overlayfs-debuginfo
< 0:1.9-1.module+el8.6.0+22399+813f5137 | < 0:1.11-1.module+el8.8.0+22334+bb93e398
- redhat•fuse-overlayfs-debugsource
< 0:1.9-1.module+el8.6.0+22399+813f5137 | < 0:1.11-1.module+el8.8.0+22334+bb93e398
- redhat•libslirp
< 0:4.4.0-1.module+el8.6.0+22399+813f5137 | < 0:4.4.0-1.module+el8.8.0+22334+bb93e398
- redhat•libslirp-debuginfo
< 0:4.4.0-1.module+el8.6.0+22399+813f5137 | < 0:4.4.0-1.module+el8.8.0+22334+bb93e398
- redhat•libslirp-debugsource
< 0:4.4.0-1.module+el8.6.0+22399+813f5137 | < 0:4.4.0-1.module+el8.8.0+22334+bb93e398
Showing first 50 affected entries in server-rendered view.
References (45)
- https://access.redhat.com/errata/RHSA-2024:8563
- https://access.redhat.com/errata/RHSA-2024:8675
- https://access.redhat.com/errata/RHSA-2024:8679
- https://access.redhat.com/errata/RHSA-2024:8686
- https://access.redhat.com/errata/RHSA-2024:8690
- https://access.redhat.com/errata/RHSA-2024:8700
- https://access.redhat.com/errata/RHSA-2024:8703
- https://access.redhat.com/errata/RHSA-2024:8707
- https://access.redhat.com/errata/RHSA-2024:8708
- https://access.redhat.com/errata/RHSA-2024:8709
- https://access.redhat.com/errata/RHSA-2024:8846
- https://access.redhat.com/errata/RHSA-2024:8984
- https://access.redhat.com/errata/RHSA-2024:8994
- https://access.redhat.com/errata/RHSA-2024:9051
- https://access.redhat.com/errata/RHSA-2024:9454
- https://access.redhat.com/errata/RHSA-2024:9459
- https://access.redhat.com/errata/RHSA-2025:2445
- https://access.redhat.com/errata/RHSA-2025:2449
- https://access.redhat.com/errata/RHSA-2025:2454
- https://access.redhat.com/errata/RHSA-2025:2701
- https://access.redhat.com/errata/RHSA-2025:2710
- https://access.redhat.com/errata/RHSA-2025:3301
- https://access.redhat.com/errata/RHSA-2025:3573
- https://access.redhat.com/security/cve/CVE-2024-9675
- https://bugzilla.redhat.com/show_bug.cgi?id=2317458
- https://nvd.nist.gov/vuln/detail/CVE-2024-9675
- https://github.com/containers/buildah/commit/aa67e5d71ee7ec07122a210baa3b13966a9e086c
- https://pkg.go.dev/vuln/GO-2024-3186
- https://github.com/containers/buildah
- https://github.com/advisories/GHSA-586p-749j-fhwp
- https://access.redhat.com/errata/RHBA-2024:10967
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8563.json
- https://www.cve.org/CVERecord?id=CVE-2024-9675
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8675.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8679.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8703.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8707.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8708.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8709.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8994.json
- https://security-tracker.debian.org/tracker/CVE-2024-9675
- https://access.redhat.com/downloads/content/package-browser/
- https://catalog.redhat.com/software/containers/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9675.json