[GO-2024-2494] Host system modification in github.com/moby/buildkit
Severity
Critical
Affected Packages
1
Fixed Packages
1
CVEs
1
A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the
feature that removes empty files created for the mountpoints into removing a
file outside the container, from the host system.
Package | Affected Version |
---|---|
pkg:golang/github.com/moby/buildkit/executor | >= 0.12.4, < 0.12.5 |
Package | Fixed Version |
---|---|
pkg:golang/github.com/moby/buildkit/executor | = 0.12.5 |
- ID
- GO-2024-2494
- Severity
- critical
- Severity from
- CVE-2024-23652
- URL
- https://pkg.go.dev/vuln/GO-2024-2494
- Published
-
2024-02-07T23:44:02
(7 months ago) - Modified
-
2024-05-14T19:19:00
(4 months ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Security Advisory | https://github.com/advisories/GHSA-4v98-7qmw-rqr8 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |