The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
{ "binaries": [ { "binary_version": "20141024-1.1", "binary_name": "obs-build" } ] }
{ "binaries": [ { "binary_version": "20170201-3", "binary_name": "obs-build" } ] }