CVE-2021-3602

medium

Description

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

References

https://ubuntu.com/security/CVE-2021-3602

https://github.com/containers/buildah/security/advisories/GHSA-7638-r9r3-rmjj

https://github.com/containers/buildah/commit/a468ce0ffd347035d53ee0e26c205ef604097fb0

https://bugzilla.redhat.com/show_bug.cgi?id=1969264

Details

Source: Mitre, NVD

Published: 2022-03-03

Updated: 2022-10-24

Risk Information

CVSS v2

Base Score: 1.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium