Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37054
HistorySep 16, 2022 - 6:55 a.m.

Information Disclosure

2022-09-1606:55:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
33
buildah
configureuidgid
information disclosure
container engine
unauthorized access

0.0005 Low

EPSS

Percentile

17.9%

github.com/containers/buildah is vulnerable to information disclosure. The vulnerability exists in configureUIDGID function in run_common.go due to improper handling of the supplementary groups in the Buildah container engine which allows an attacker to gain access to containers and perform unauthorized actions.