CVE-2024-7387

Source
https://cve.org/CVERecord?id=CVE-2024-7387
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7387.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7387
Aliases
Published
2024-09-16T23:58:35Z
Modified
2026-08-13T03:51:59Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Openshift/builder: path traversal allows command injection in privileged buildcontainer using docker build strategy
Details

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the spec.source.secrets.secret.destinationDir attribute of the BuildConfig definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-250"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7387.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "0b62633adfa2836465202bc851885e078ec888d1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/openshift/builder

Affected ranges

Type
GIT
Repo
https://github.com/openshift/builder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v4.*
v4.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7387.json"