Vulnerability Report: GO-2024-2493
- CVE-2024-23651, GHSA-m3r6-h7wv-7xxv
- Affects: github.com/moby/buildkit
- Published: Feb 13, 2024
- Modified: May 20, 2024
Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.12.5
3 unexported affected symbols
- sub
- submounts.cleanup
- submounts.subMount
-
before v0.12.5
Aliases
References
Credits
- @rmcnamara-snyk
Feedback
See anything missing or incorrect?
Suggest an edit to this report.