CVE-2020-10696
published 2020-03-31CVE-2020-10696: A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.60%
83.7th percentile
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| buildah_project | buildah | < 1.14.5 | 1.14.5 |
| debian | golang-github-containers-buildah | < golang-github-containers-buildah 1.11.6-2 (bookworm) | golang-github-containers-buildah 1.11.6-2 (bookworm) |
| github.com | containers_buildah | >= 0 < 1.14.4 | 1.14.4 |
| red_hat | buildah | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
buildah: Crafted input tar file may lead to local file overwrite during image build process
vendor_redhat·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CWE-22 buildah: Crafted input tar file may lead to local file overwrite during image build process
buildah: Crafted input tar file may lead to local file overwrite during image build process
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
A path traversal flaw was found in Buildah. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Statement: While OpenShift Container Platform does include the vulnerable buildah code, it doesn't make use of the vulnerable function. Podman is also included in OpenShift Container Platform, but
Debian
CVE-2020-10696: golang-github-containers-buildah - A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw ...
vendor_debian·2020·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696: golang-github-containers-buildah - A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw ...
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Scope: local
bookworm: resolved (fixed in 1.11.6-2)
bullseye: resolved (fixed in 1.11.6-2)
forky: resolved (fixed in 1.11.6-2)
sid: resolved (fixed in 1.11.6-2)
trixie: resolved (fixed in 1.11.6-2)
OSV
Path Traversal in Buildah in github.com/containers/buildah
osv·2024-08-21
CVE-2020-10696 Path Traversal in Buildah in github.com/containers/buildah
Path Traversal in Buildah in github.com/containers/buildah
Path Traversal in Buildah in github.com/containers/buildah
GHSA
Path Traversal in Buildah
ghsa·2021-05-18
CVE-2020-10696 [HIGH] CWE-22 Path Traversal in Buildah
Path Traversal in Buildah
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
### Specific Go Packages Affected
github.com/containers/buildah/imagebuildah
OSV
Path Traversal in Buildah
osv·2021-05-18
CVE-2020-10696 [HIGH] Path Traversal in Buildah
Path Traversal in Buildah
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
### Specific Go Packages Affected
github.com/containers/buildah/imagebuildah
OSV
CVE-2020-10696: A path traversal flaw was found in Buildah in versions before 1
osv·2020-03-31·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696: A path traversal flaw was found in Buildah in versions before 1
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-31]
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-31]
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-31]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-31.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-30]
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-30]
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-31]
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-31]
CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-31]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-31.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Dis
Bugzilla
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [openstack-rdo]
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [openstack-rdo]
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Dis
Bugzilla
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process
CVE-2020-10696 buildah: Crafted input tar file may lead to local file overwrite during image build process
During buildah image building process a crafted tar file containing symlinks may lead buildah to overwrite any file which the running uid have write permissions, compromising confidentiality, integrity and possibly allowing code execution.
Discussion:
Acknowledgments:
Name: Erik Sjölund
---
Upstream commit for this issue:
https://github.com/containers/buildah/commit/c61925b8936e93a5e900f91b653a846f7ea3a9ed
---
Created buildah tracking bugs for this issue:
Affects: fedora-30 [bug 1817687]
Affects: fedora-31 [bug 1817688]
Affects: openstack-rdo [bug 1817693]
Created podman tracking bugs for this issue:
Affects: fedora-30 [bug 1817691]
Affects: fedora-31 [bug 1817692]
Affects
Bugzilla
CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-30]
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-30]
CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Dis
Bugzilla
CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [openstack-rdo]
bugzilla·2020-03-26·CVSS 8.8
CVE-2020-10696 [HIGH] CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [openstack-rdo]
CVE-2020-10696 podman: buildah: Crafted input tar file may lead to local file overwrite during image build process [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
https://access.redhat.com/security/cve/cve-2020-10696https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10696https://github.com/containers/buildah/pull/2245https://access.redhat.com/security/cve/cve-2020-10696https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10696https://github.com/containers/buildah/pull/2245
2020-03-31
Published