GHSA-4crw-w8pw-2hmf
GitHub Security Advisory
Buildah (as part of Podman) vulnerable to Link Following
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Affected Packages
Go
github.com/containers/podman/v4
Affected versions:
0
(fixed in 4.5.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 2, 2025 6:46 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.