[GO-2024-2494] Host system modification in github.com/moby/buildkit

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the
feature that removes empty files created for the mountpoints into removing a
file outside the container, from the host system.

Package Affected Version
pkg:golang/github.com/moby/buildkit/executor >= 0.12.4, < 0.12.5
Package Fixed Version
pkg:golang/github.com/moby/buildkit/executor = 0.12.5
ID
GO-2024-2494
Severity
critical
Severity from
CVE-2024-23652
URL
https://pkg.go.dev/vuln/GO-2024-2494
Published
2024-02-07T23:44:02
(7 months ago)
Modified
2024-05-14T19:19:00
(4 months ago)
Other Advisories
Source # ID Name URL
Security Advisory https://github.com/advisories/GHSA-4v98-7qmw-rqr8
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/github.com/moby/buildkit/executor github.com/moby/buildkit executor = 0.12.5
Affected pkg:golang/github.com/moby/buildkit/executor github.com/moby/buildkit executor >= 0.12.4 < 0.12.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...