PT-2026-97204 · Unknown+1 · Buildstream+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache BuildStream versions prior to 2.8.1
Description
An improper link resolution issue exists in the
tar source plugin when running on Python versions prior to 3.12. This allows malicious source tarballs to write files on the host system with the privileges of the user running BuildStream by using symlinks during the source fetching process. Symlinks are symbolic links, which are files that point to another file or directory.Recommendations
Upgrade to version 2.8.1.
Use Python version 3.12 or newer.
Only use trusted sources in BuildStream projects.
Track source tarballs by pinning their SHA256 hash.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buildstream
Python