CVE-2020-10696: Buildah Project Buildah
High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Affected products
- Buildah Project Buildah: before 1.14.5 (fixed in 1.14.5)
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Openshift Container Platform: version 3.11 only
Published 2020-03-31. Last modified 2026-06-17.