Vulnerability Report: GO-2024-2494
- CVE-2024-23652, GHSA-4v98-7qmw-rqr8
- Affects: github.com/moby/buildkit
- Published: Feb 12, 2024
A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system.
For detailed information about this vulnerability, visit https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8.
Affected Packages
-
PathVersionsSymbols
-
before v0.12.5
Aliases
References
- https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8
- https://github.com/moby/buildkit/pull/4603
- https://github.com/moby/buildkit/releases/tag/v0.12.5
- https://vuln.go.dev/ID/GO-2024-2494.json
Credits
- @rmcnamara-snyk
Feedback
See anything missing or incorrect?
Suggest an edit to this report.