Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-3602
Description:An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).
Test IDs: 1.3.6.1.4.1.25623.1.0.879896   1.3.6.1.4.1.25623.1.0.879856   1.3.6.1.4.1.25623.1.0.879857   1.3.6.1.4.1.25623.1.0.879851   1.3.6.1.4.1.25623.1.0.879863   1.3.6.1.4.1.25623.1.0.879848   1.3.6.1.4.1.25623.1.0.879852   1.3.6.1.4.1.25623.1.0.879891  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-3602
https://bugzilla.redhat.com/show_bug.cgi?id=1969264
https://bugzilla.redhat.com/show_bug.cgi?id=1969264
https://github.com/containers/buildah/commit/a468ce0ffd347035d53ee0e26c205ef604097fb0
https://github.com/containers/buildah/commit/a468ce0ffd347035d53ee0e26c205ef604097fb0
https://github.com/containers/buildah/security/advisories/GHSA-7638-r9r3-rmjj
https://github.com/containers/buildah/security/advisories/GHSA-7638-r9r3-rmjj
https://ubuntu.com/security/CVE-2021-3602
https://ubuntu.com/security/CVE-2021-3602




© 1998-2025 E-Soft Inc. All rights reserved.