github.com/containers/storage is vulnerable to Path Traversal
65
Medium Risk
Affected versions of this package are vulnerable to path traversal. The containers/storage library improperly validates symlinks when attempting to read /etc/passwd inside the container, which allows an attacker to exploit this weakness and read arbitrary files on the host.
You are affected if you are using a version that falls within the vulnerable range.
github.com/containers/storage is vulnerable to Path Traversal in versions 1.17.0 - 1.51.1 and 1.52.0 - 1.55.0.
Upgrade the github.com/containers/storage library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant