| id: GO-2022-0345 |
| modules: |
| - module: github.com/containers/buildah |
| versions: |
| - fixed: 1.22.0 |
| vulnerable_at: 1.21.0 |
| packages: |
| - package: github.com/containers/buildah/chroot |
| symbols: |
| - RunUsingChroot |
| summary: Environment variable leakage in github.com/containers/buildah |
| description: |- |
| The RunUsingChroot function unintentionally propagates environment variables |
| from the current process to the child process. |
| published: 2022-07-15T23:30:21Z |
| cves: |
| - CVE-2021-3602 |
| ghsas: |
| - GHSA-7638-r9r3-rmjj |
| references: |
| - fix: https://github.com/containers/buildah/commit/a468ce0ffd347035d53ee0e26c205ef604097fb0 |
| review_status: REVIEWED |