A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a RUN instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-9675.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4_ppc64le"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.4"
}
]
}
]