PT-2026-107537 · Red Hat · Openshift Serverless+3

CVE-2026-107174

·

Publicado

2026-10-07

·

Atualizado

2026-10-07

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-107174

Produtos afetados

Openshift Serverless
Openshift Source-To-Image
Red Hat Openshift Container Platform 4
Red Hat Web Terminal