File tree 2 files changed +20
-19
lines changed
2 files changed +20
-19
lines changed Original file line number Diff line number Diff line change 21
21
"events" : [
22
22
{
23
23
"introduced" : " 0"
24
+ },
25
+ {
26
+ "fixed" : " 1.37.4"
24
27
}
25
28
]
26
29
}
106
109
"events" : [
107
110
{
108
111
"introduced" : " 0"
112
+ },
113
+ {
114
+ "fixed" : " 5.2.4"
109
115
}
110
116
]
111
117
}
119
125
"url" : " https://github.com/advisories/GHSA-fhqq-8f65-5xfc"
120
126
},
121
127
{
122
- "type" : " ADVISORY" ,
123
- "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-9407"
124
- },
125
- {
126
- "type" : " WEB" ,
127
- "url" : " https://access.redhat.com/security/cve/CVE-2024-9407"
128
+ "type" : " FIX" ,
129
+ "url" : " https://github.com/containers/buildah/commit/e4e2ad5ca2088d7c388109394135ead7aaf1f4f4"
128
130
},
129
131
{
130
132
"type" : " WEB" ,
131
- "url" : " https://bugzilla.redhat. com/show_bug.cgi?id=2315887 "
133
+ "url" : " https://github. com/containers/podman/releases/tag/v5.2.4 "
132
134
}
133
135
],
134
136
"database_specific" : {
135
137
"url" : " https://pkg.go.dev/vuln/GO-2024-3169" ,
136
- "review_status" : " UNREVIEWED "
138
+ "review_status" : " REVIEWED "
137
139
}
138
140
}
Original file line number Diff line number Diff line change 1
1
id : GO-2024-3169
2
2
modules :
3
3
- module : github.com/containers/buildah
4
- unsupported_versions :
5
- - last_affected : 1.37.3
6
- vulnerable_at : 1.37.4
4
+ versions :
5
+ - fixed : 1.37.4
6
+ vulnerable_at : 1.37.3
7
7
- module : github.com/containers/podman
8
8
vulnerable_at : 1.9.3
9
9
- module : github.com/containers/podman/v2
@@ -13,20 +13,19 @@ modules:
13
13
- module : github.com/containers/podman/v4
14
14
vulnerable_at : 4.9.5
15
15
- module : github.com/containers/podman/v5
16
- unsupported_versions :
17
- - last_affected : 5.2.3
18
- vulnerable_at : 5.2.4
16
+ versions :
17
+ - fixed : 5.2.4
18
+ vulnerable_at : 5.2.3
19
19
summary : Improper Input Validation in Buildah and Podman in github.com/containers/buildah
20
20
cves :
21
21
- CVE-2024-9407
22
22
ghsas :
23
23
- GHSA-fhqq-8f65-5xfc
24
24
references :
25
25
- advisory : https://github.com/advisories/GHSA-fhqq-8f65-5xfc
26
- - advisory : https://nvd.nist.gov/vuln/detail/CVE-2024-9407
27
- - web : https://access.redhat.com/security/cve/CVE-2024-9407
28
- - web : https://bugzilla.redhat.com/show_bug.cgi?id=2315887
26
+ - fix : https://github.com/containers/buildah/commit/e4e2ad5ca2088d7c388109394135ead7aaf1f4f4
27
+ - web : https://github.com/containers/podman/releases/tag/v5.2.4
29
28
source :
30
29
id : GHSA-fhqq-8f65-5xfc
31
- created : 2024-10-08T10:57:52.867555-04 :00
32
- review_status : UNREVIEWED
30
+ created : 2024-12-11T15:38:28.529084-05 :00
31
+ review_status : REVIEWED
You can’t perform that action at this time.
0 commit comments