CVE-2020-10696: Path Traversal
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Other sources
A path traversal flaw was found in Buildah. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
During buildah image building process a crafted tar file containing symlinks may lead buildah to overwrite any file which the running uid have write permissions, compromising confidentiality, integrity and possibly allowing code execution.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 0:1.11.6-11.el7_8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.6.4-18.el7_8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.4.2-6.rhaos4.2.el8 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 0:1.6.4-10.rhaos4.3.el8 - Upgrade
Upgrade
go/github.com/containers/buildahto a version that resolves this vulnerability.Fixed in 1.14.4 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.14.5 - Upgrade
Upgrade
Buildahto a version that resolves this vulnerability.Fixed in 1.14.5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-10696?
CVE-2020-10696 is a path traversal vulnerability found in Buildah.
How does CVE-2020-10696 affect Buildah?
CVE-2020-10696 allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
What is the severity level of CVE-2020-10696?
CVE-2020-10696 has a severity level of 8.8 (high).
Which versions of Buildah are affected by CVE-2020-10696?
Versions of Buildah before 1.14.5 are affected by CVE-2020-10696.
How can I fix CVE-2020-10696 in Buildah?
To fix CVE-2020-10696 in Buildah, update to version 1.14.5 or later.