buildstream@1.93.0.dev0

A framework for modelling build pipelines in YAML

  • latest version

    2.8.1.dev0

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    14 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the buildstream package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Symlink Attack

    BuildStream is an A framework for modelling build pipelines in YAML

    Affected versions of this package are vulnerable to Symlink Attack in the tar source plugin when handling archive extraction. An attacker can modify or overwrite arbitrary files on the host system by supplying a malicious tarball containing symlinks during the source fetching process. This is only exploitable if the environment is running on Python versions earlier than 3.12 and the user explicitly fetches an untrusted archive.

    How to fix Symlink Attack?

    Upgrade BuildStream to version 2.8.1 or higher.

    [,2.8.1)