blob: 6afa2107c02508a1d6f3c6327c8211c8fdf07120 [file] [log] [blame]
id: GO-2024-3129
modules:
- module: github.com/openshift/builder
unsupported_versions:
- last_affected: 4.0.0
vulnerable_at: 4.0.0+incompatible
summary: |-
OpenShift Builder has a path traversal, allows command injection in privileged
BuildContainer in github.com/openshift/builder
cves:
- CVE-2024-7387
ghsas:
- GHSA-qqv8-ph7f-h3f7
references:
- advisory: https://github.com/advisories/GHSA-qqv8-ph7f-h3f7
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-7387
- fix: https://github.com/openshift/builder/commit/0b62633adfa2836465202bc851885e078ec888d1
- web: https://access.redhat.com/security/cve/CVE-2024-7387
- web: https://bugzilla.redhat.com/show_bug.cgi?id=2302259
source:
id: GHSA-qqv8-ph7f-h3f7
created: 2024-09-18T13:42:07.618082148Z
review_status: UNREVIEWED