CVE-2021-3602

CVSS v3.1 5.5 (Medium)
55% Progress
CVSS v2.0 1.9 (Low)
19% Progress
EPSS 0.04 % (16th)
0.04% Progress
Affected Products 4
Advisories 19

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-03-03 19:15:08
(2 years ago)
Updated Date
2022-10-24 14:22:45
(23 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Buildah Project Buildah prior 1.16.8 version cpe:2.3:a:buildah_project:buildah < 1.16.8
  Buildah Project Buildah from 1.17.0 version and prior 1.17.2 version cpe:2.3:a:buildah_project:buildah >= 1.17.0 < 1.17.2
  Buildah Project Buildah from 1.19.0 version and prior 1.19.9 version cpe:2.3:a:buildah_project:buildah >= 1.19.0 < 1.19.9
  Buildah Project Buildah from 1.21.0 version and prior 1.21.3 version cpe:2.3:a:buildah_project:buildah >= 1.21.0 < 1.21.3

Configuration #2

    CPE23 From Up To
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
  Redhat Enterprise Linux for Ibm Z Systems 8.0 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0
  Redhat Enterprise Linux for Power Little Endian 8.0 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...