QID 996492
Date Published: 2024-01-04
QID 996492: GO (Go) Security Update for github.com/buildkite/elastic-ci-stack-for-aws/v6 (GHSA-r5hg-349q-mg2q)
A time-of-check-time-of-use race condition vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to bypass a symbolic link check for the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r5hg-349q-mg2q for updates and patch information.
Vendor References
- GHSA-r5hg-349q-mg2q -
github.com/advisories/GHSA-r5hg-349q-mg2q
CVEs related to QID 996492
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r5hg-349q-mg2q | github.com/buildkite/elastic-ci-stack-for-aws/v6 |
|