MEDIUM 5.3 Go
Buildah (as part of Podman) vulnerable to Link Following
GHSA-4crw-w8pw-2hmf · CVE-2022-4122 · GO-2022-1151
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Ready to move
Start Securing
Free, no credit card | First findings in minutes