Описание
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.31.2 (исключая)
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00314
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
debian
около 1 месяца назад
A custom client can produce such an upload request to the BuildKit dae ...
EPSS
Процентиль: 24%
0.00314
Низкий
7.5 High
CVSS3
Дефекты
CWE-22