github.com/containers/buildah is vulnerable to Improper Privilege Management
86
High Risk
Affected versions of the package are vulnerable to improper privilege management. Users running containers with root privileges allow a container to run with read/write access to the host system files when SELinux is not enabled. With SELinux enabled, some read access is allowed.
You are affected if you are using a version that falls within the vulnerable range.
github.com/containers/buildah is vulnerable to Improper Privilege Management in versions 1.35.0 - 1.35.0, 1.34.0 - 1.34.2, 1.33.0 - 1.33.6, 1.32.0 - 1.32.2, 1.31.0 - 1.31.4, 1.29.0 - 1.29.2, 1.27.0 - 1.27.3, 1.26.0 - 1.26.6 and 1.24.0 - 1.24.6.
Upgrade the github.com/containers/buildah library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant