A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.
https://access.redhat.com/errata/RHSA-2024:6705
https://access.redhat.com/errata/RHSA-2024:6691
https://access.redhat.com/errata/RHSA-2024:6689
https://access.redhat.com/errata/RHSA-2024:6687
https://access.redhat.com/errata/RHSA-2024:6685
https://github.com/fatcatresearch/cve-2024-7387
https://github.com/0xSigSegv0x00/cve-2024-7387
https://stuxxn.github.io/advisory/2024/10/02/openshift-build-docker-priv-esc.html
https://github.com/openshift/builder/commit/0b62633adfa2836465202bc851885e078ec888d1
Published: 2024-09-17
Updated: 2026-08-11
Base Score: 8.3
Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C
Severity: High
Base Score: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
Base Score: 6.4
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Severity: Medium
EPSS: 0.00289