A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2144983 | third party advisory issue tracking |
https://github.com/containers/podman/pull/16315 | third party advisory patch |