{
  "threat_severity" : "Important",
  "public_date" : "2020-03-26T00:00:00Z",
  "bugzilla" : {
    "description" : "buildah: Crafted input tar file may lead to local file overwrite during image build process",
    "id" : "1817651",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1817651"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.", "A path traversal flaw was found in Buildah. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions." ],
  "statement" : "While OpenShift Container Platform does include the vulnerable buildah code, it doesn't make use of the vulnerable function. Podman is also included in OpenShift Container Platform, but it isn't used to perform a build, so it has been given a low impact rating.\nOpenShift Container Platform 3.11 now used podman from the RHEL Extra repository, and not the podman package shipped in the OpenShift 3.11 RPM repository. This issue is fixed in podman in RHEL Extras so we won't fix the podman package shipped in the OpenShift 3.11 RPM repository.",
  "acknowledgement" : "Red Hat would like to thank Erik Sjölund for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7 Extras",
    "release_date" : "2020-05-12T00:00:00Z",
    "advisory" : "RHSA-2020:2116",
    "cpe" : "cpe:/a:redhat:rhel_extras_other:7",
    "package" : "buildah-0:1.11.6-11.el7_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extras",
    "release_date" : "2020-05-12T00:00:00Z",
    "advisory" : "RHSA-2020:2117",
    "cpe" : "cpe:/a:redhat:rhel_extras_other:7",
    "package" : "podman-0:1.6.4-18.el7_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2020-04-28T00:00:00Z",
    "advisory" : "RHSA-2020:1926",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "container-tools:1.0-8020020200420104655.28c38760"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2020-04-28T00:00:00Z",
    "advisory" : "RHSA-2020:1931",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "container-tools:2.0-8020020200420175838.28c38760"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2020-04-28T00:00:00Z",
    "advisory" : "RHSA-2020:1932",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "container-tools:rhel8-8020020200420180128.28c38760"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.1",
    "release_date" : "2020-04-22T00:00:00Z",
    "advisory" : "RHSA-2020:1449",
    "cpe" : "cpe:/a:redhat:openshift:4.1::el8",
    "package" : "podman-0:1.0.2-4.dev.git96ccc2e.rhaos4.1.el8",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.2",
    "release_date" : "2020-04-14T00:00:00Z",
    "advisory" : "RHSA-2020:1401",
    "cpe" : "cpe:/a:redhat:openshift:4.2::el8",
    "package" : "podman-0:1.4.2-6.rhaos4.2.el8",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.3",
    "release_date" : "2020-04-14T00:00:00Z",
    "advisory" : "RHSA-2020:1396",
    "cpe" : "cpe:/a:redhat:openshift:4.3::el8",
    "package" : "podman-0:1.6.4-10.rhaos4.3.el8",
    "impact" : "low"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Fix deferred",
    "package_name" : "atomic-openshift",
    "cpe" : "cpe:/a:redhat:openshift:3.11",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Will not fix",
    "package_name" : "podman",
    "cpe" : "cpe:/a:redhat:openshift:3.11",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-docker-builder",
    "cpe" : "cpe:/a:redhat:openshift:4",
    "impact" : "low"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-10696\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-10696" ],
  "name" : "CVE-2020-10696",
  "csaw" : false
}