CLEANSTART-2024-XJ51471

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2024/CLEANSTART-2024-XJ51471.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2024-XJ51471
Upstream
Published
2026-09-30T19:15:33Z
Modified
2026-10-01T01:00:05Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers
Details

Security vulnerability affects the buildah package. A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers.

References

Affected packages

CleanStart / buildah

Package

Name
buildah

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.35.4-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2024/CLEANSTART-2024-XJ51471.json"