6.4
CVE-2026-107174
- EPSS -
- Veröffentlicht 07.10.2026 14:34:51
- Zuletzt bearbeitet 07.10.2026 17:16:53
- Erkennungen
Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction
A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
OpenShift Serverless
Default Statusaffected
HerstellerRed Hat
≫
Produkt
OpenShift Serverless
Default Statusaffected
HerstellerRed Hat
≫
Produkt
OpenShift Serverless
Default Statusaffected
HerstellerRed Hat
≫
Produkt
OpenShift Source-to-Image (S2I)
Default Statusaffected
HerstellerRed Hat
≫
Produkt
OpenShift Source-to-Image (S2I)
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Web Terminal
Default Statusaffected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.4 | 3.1 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
|
CWE-61 UNIX Symbolic Link (Symlink) Following
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
https://access.redhat.com/security/cve/CVE-2026-107174
https://bugzilla.redhat.com/show_bug.cgi?id=2547419