CVE-2020-10696
HIGH8.8EPSS 0.26%Path Traversal in Buildah in github.com/containers/buildah
Published: 5/18/2021Modified: 4/28/2026
Description
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Affected packages (3)
- Debian/golang-github-containers-buildahfrom 0, < 1.11.6-2
- Go/github.com/containers/buildahfrom 0, < 1.14.4
- Go/github.com/containers/buildahfrom 0, < 1.14.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References (9)
- ADVISORYhttps://github.com/advisories/GHSA-fx8w-mjvm-hvpc
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-10696
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-10696
- PATCHhttps://github.com/containers/buildah
- WEBhttps://access.redhat.com/security/cve/cve-2020-10696
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1817651
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10696
- WEBhttps://github.com/containers/buildah/pull/2245
- WEBhttps://pkg.go.dev/vuln/GO-2022-0828