← Back

CVE-2024-9675

nvd nist
Published: Oct 9, 2024Modified: Aug 25, 2025

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.5
Source: NVD

Description

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

Affected (45)

Buildah
13 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
44 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 8.0
Version 9.0
Redhat
Version 8.8
Version 9.0
Version 9.2
Version 9.4
Redhat
Version 8.0_aarch64
Version 9.0_aarch64
Redhat
Version 8.8_aarch64
Version 9.0_aarch64
Version 9.2_aarch64
Version 9.4_aarch64
Redhat
Version 8.0_s390x
Version 9.0_s390x
Redhat
Version 8.8_s390x
Version 9.0_s390x
Version 9.2_s390x
Version 9.4_s390x
Redhat
Version 8.0_ppc64le
Version 9.0_ppc64le
Redhat
Version 8.8_ppc64le
Version 9.0_ppc64le
Version 9.2_ppc64le
Version 9.4_ppc64le
Redhat
Version 8.6
Version 9.2
Version 9.4
Redhat
Version 8.6_ppc64le
Version 8.8_ppc64le
Version 9.0_ppc64le
Version 9.2_ppc64le
Version 9.4_ppc64le
Redhat
Version 8.6
Version 8.8
Redhat
Version 8.6
Version 8.8
Version 9.0
Version 9.2
Version 9.4
Redhat
Version 4.13
Version 4.14
Version 4.15
Version 4.16
Version 4.17

References (25)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue Tracking

Timeline

No history available yet.