Описание
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.30.0 (включая) до 0.31.2 (исключая)
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.00202
Низкий
7.5 High
CVSS3
Дефекты
CWE-88
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 1 месяца назад
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
CVSS3: 7.5
debian
около 1 месяца назад
BuildKit custom frontends or clients using the raw low-level API can s ...
EPSS
Процентиль: 10%
0.00202
Низкий
7.5 High
CVSS3
Дефекты
CWE-88