Improper Link Resolution Before File Access ('Link Following') Affecting github.com/buildkite/elastic-ci-stack-for-aws package, versions <5.22.5>=6.0.0 <6.7.0


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMBUILDKITEELASTICCISTACKFORAWS-6144857
  • published5 Jan 2024
  • disclosed22 Dec 2023
  • creditNick Nam

Introduced: 22 Dec 2023

CVE-2023-43116  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade github.com/buildkite/elastic-ci-stack-for-aws to version 5.22.5, 6.7.0 or higher.

Overview

github.com/buildkite/elastic-ci-stack-for-aws is a platform for running fast, secure, and scalable continuous integration pipelines on your own infrastructure.

Affected versions of this package are vulnerable to Improper Link Resolution Before File Access ('Link Following') via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script. An attacker can change ownership of arbitrary directories by exploiting this vulnerability.

CVSS Scores

version 3.1