Vulnerability Report: GO-2024-2494

A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system.

For detailed information about this vulnerability, visit https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL