Loading HuntDB...

GHSA-4crw-w8pw-2hmf

GitHub Security Advisory

Buildah (as part of Podman) vulnerable to Link Following

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

Affected Packages

Go github.com/containers/podman/v4
Affected versions: 0 (fixed in 4.5.0)

Related CVEs

Key Information

GHSA ID
GHSA-4crw-w8pw-2hmf
Published
December 8, 2022 6:30 PM
Last Modified
December 12, 2022 8:44 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/containers/podman/v4
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.