CVE-2020-27534: Path Traversal
(updated )
util/binfmt_misc/check.go
in Builder of Docker Engine calls os.OpenFile
with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir
call.
References
Detect and mitigate CVE-2020-27534 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →