Vulnerability Report: GO-2024-3129
- CVE-2024-7387, GHSA-qqv8-ph7f-h3f7
- Affects: github.com/openshift/builder
- Published: Sep 18, 2024
- Unreviewed
OpenShift Builder has a path traversal, allows command injection in privileged BuildContainer in github.com/openshift/builder
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-qqv8-ph7f-h3f7 or https://nvd.nist.gov/vuln/detail/CVE-2024-7387.
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
Aliases
References
- https://github.com/advisories/GHSA-qqv8-ph7f-h3f7
- https://nvd.nist.gov/vuln/detail/CVE-2024-7387
- https://github.com/openshift/builder/commit/0b62633adfa2836465202bc851885e078ec888d1
- https://access.redhat.com/security/cve/CVE-2024-7387
- https://bugzilla.redhat.com/show_bug.cgi?id=2302259
- https://vuln.go.dev/ID/GO-2024-3129.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.