THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-9675 (HIGH 7.8) — A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as lo

[NVD] CVE-2024-9675 (HIGH 7.8) — A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as lo

lownvdPublished 2024-10-09

CVE-2024-9675 CVSS: 7.8 HIGH Published: 2024-10-09T15:15:17.837

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running B

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-9675