Executive brief
Buildah is a tool used to create and manage container images. A security flaw allows a user to bypass restrictions and gain unauthorized access to files on the host computer by mounting them into a container during the build process. This could lead to the exposure or modification of sensitive data if the user running the build has access to those files on the host system.
Technical details
A path traversal vulnerability (CWE-22) exists in Buildah's cache mount implementation. The software fails to properly validate that user-specified paths for cache mounts are restricted to the designated cache directory. An attacker with the ability to provide a Containerfile can use a `RUN` instruction to mount arbitrary host directories with read/write permissions, provided the user executing Buildah has the necessary filesystem permissions for those host paths. This allows for unauthorized data access or modification on the host system. The issue is resolved in Buildah version 1.38.0.
Affected products
- containers Buildah < 1.38.0
Timeline
- 2024-10-09: disclosed
- 2024-10-09: advisory
- 2024-10-09: patched: Version 1.38.0 released