Логотип exploitDog
bind:CVE-2024-23652
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-23652

Количество 13

Количество 13

ubuntu логотип

CVE-2024-23652

около 2 лет назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2024-23652

около 2 лет назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2024-23652

около 2 лет назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

CVSS3: 10
EPSS: Низкий
msrc логотип

CVE-2024-23652

около 2 лет назад

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4v98-7qmw-rqr8

около 2 лет назад

BuildKit vulnerable to possible host system access from mount stub cleaner

CVSS3: 10
EPSS: Низкий
fstec логотип

BDU:2024-01029

около 2 лет назад

Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю удалить произвольные файлы за пределами контейнера

CVSS3: 10
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1469-1

почти 2 года назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0587-1

почти 2 года назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0586-2

почти 2 года назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0586-1

почти 2 года назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3120-1

больше 1 года назад

Security update for buildah, docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03545-1

4 месяца назад

Security update for docker-stable

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03540-1

4 месяца назад

Security update for docker-stable

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-23652

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

CVSS3: 10
5%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-23652

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

CVSS3: 7.8
5%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-23652

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

CVSS3: 10
5%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 9.1
5%
Низкий
около 2 лет назад
github логотип
GHSA-4v98-7qmw-rqr8

BuildKit vulnerable to possible host system access from mount stub cleaner

CVSS3: 10
5%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-01029

Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю удалить произвольные файлы за пределами контейнера

CVSS3: 10
5%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1469-1

Security update for docker

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:0587-1

Security update for docker

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:0586-2

Security update for docker

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:0586-1

Security update for docker

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3120-1

Security update for buildah, docker

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:03545-1

Security update for docker-stable

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03540-1

Security update for docker-stable

4 месяца назад

Уязвимостей на страницу