QID 996498
Date Published: 2024-01-04
QID 996498: GO (Go) Security Update for github.com/buildkite/elastic-ci-stack-for-aws/v6 (GHSA-7c44-7j7v-w554)
A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7c44-7j7v-w554 for updates and patch information.
Vendor References
- GHSA-7c44-7j7v-w554 -
github.com/advisories/GHSA-7c44-7j7v-w554
CVEs related to QID 996498
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7c44-7j7v-w554 | github.com/buildkite/elastic-ci-stack-for-aws/v6 |
|