Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-9675

Published: October 9, 2024Last modified: February 28, 2025

Description

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbuildahFixed (1.37.5-r0)
podmanFixed (5.2.5-r0)
StreambuildahFixed (1.37.5-r0)
podmanFixed (5.2.5-r1)

References

ON THIS PAGE