Количество 12
Количество 12
BDU:2026-07210
Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260430-73-0005
Уязвимость buildkit
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in ...
GHSA-4vrq-3vrq-g6gg
BuildKit Git URL subdir component can cause access to restricted files
openSUSE-SU-2026:20814-1
Security update for docker-stable
SUSE-SU-2026:2120-1
Security update for docker-stable
SUSE-SU-2026:2578-1
Security update for docker-stable
openSUSE-SU-2026:20702-1
Security update for trivy
openSUSE-SU-2026:20809-1
Security update for trivy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07210 Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
ROS-20260430-73-0005 Уязвимость buildkit | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-4vrq-3vrq-g6gg BuildKit Git URL subdir component can cause access to restricted files | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20814-1 Security update for docker-stable | 2 месяца назад | |||
SUSE-SU-2026:2120-1 Security update for docker-stable | 2 месяца назад | |||
SUSE-SU-2026:2578-1 Security update for docker-stable | около 1 месяца назад | |||
openSUSE-SU-2026:20702-1 Security update for trivy | 3 месяца назад | |||
openSUSE-SU-2026:20809-1 Security update for trivy | 3 месяца назад |
Уязвимостей на страницу