VDB
Sign up
MEDIUM5.5

GHSA-2w4f-9fgg-q2v9

melange has a path traversal in license-path which allows reading files outside workspace

Quick fix

GHSA-2w4f-9fgg-q2v9 — chainguard.dev/melange: upgrade to the fixed version with the command below.

go get chainguard.dev/melange@v0.40.3

Details

An attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios) could read arbitrary files from the host system. The `LicensingInfos` function in `pkg/config/config.go` reads license files specified in `copyright[].license-path` without validating that paths remain within the workspace directory, allowing path traversal via `../` sequences. The contents of the traversed file are embedded into the generated SBOM as license text, enabling exfiltration of sensitive data through build artifacts. Fix: Merged in commit 2f95c9f4 Acknowledgements melange thanks Oleh Konko (@1seal) from 1seal for discovering and reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/chainguard.dev/melange
Introduced in: 0.14.0Fixed in: 0.40.3
Fixgo get chainguard.dev/melange@v0.40.3

References