Количество 15
Количество 15
GHSA-4vrq-3vrq-g6gg
BuildKit Git URL subdir component can cause access to restricted files
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in ...
ROS-20260430-80-0005
Уязвимость buildkit
BDU:2026-07210
Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
openSUSE-SU-2026:20814-1
Security update for docker-stable
SUSE-SU-2026:2120-1
Security update for docker-stable
ROS-20260812-80-0015
Уязвимость podman
ROS-20260812-73-0012
Уязвимость podman
ROS-20260430-73-0005
Уязвимость buildkit
SUSE-SU-2026:2578-1
Security update for docker-stable
openSUSE-SU-2026:20702-1
Security update for trivy
openSUSE-SU-2026:20809-1
Security update for trivy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4vrq-3vrq-g6gg BuildKit Git URL subdir component can cause access to restricted files | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in ... | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
ROS-20260430-80-0005 Уязвимость buildkit | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
BDU:2026-07210 Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
openSUSE-SU-2026:20814-1 Security update for docker-stable | 4 месяца назад | |||
SUSE-SU-2026:2120-1 Security update for docker-stable | 4 месяца назад | |||
ROS-20260812-80-0015 Уязвимость podman | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260812-73-0012 Уязвимость podman | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260430-73-0005 Уязвимость buildkit | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:2578-1 Security update for docker-stable | 3 месяца назад | |||
openSUSE-SU-2026:20702-1 Security update for trivy | 5 месяцев назад | |||
openSUSE-SU-2026:20809-1 Security update for trivy | 4 месяца назад |
Уязвимостей на страницу