Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p26-698r-w4hx

Опубликовано: 31 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

BuildKit vulnerable to possible panic when incorrect parameters sent from frontend

Impact

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

Patches

The issue has been fixed in v0.12.5

Workarounds

Avoid using BuildKit frontends from untrusted sources. A frontend image is usually specified as the #syntax line on your Dockerfile, or with --frontend flag when using buildctl build command.

References

Пакеты

Наименование

github.com/moby/buildkit

go
Затронутые версииВерсия исправления

< 0.12.5

0.12.5

EPSS

Процентиль: 25%
0.00081
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

CVSS3: 5.3
redhat
больше 1 года назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

CVSS3: 5.3
nvd
больше 1 года назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

CVSS3: 5.3
msrc
больше 1 года назад

Описание отсутствует

suse-cvrf
5 месяцев назад

Security update for docker-stable

EPSS

Процентиль: 25%
0.00081
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-754