CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
21.7%
A vulnerability was found in the Moby Builder Toolkit, which arose from BuildKit’s attempts to clean up temporarily added directories after use. A malicious BuildKit frontend or Dockerfile using RUN --mount could deceive the feature responsible for removing empty files created for the mount points, potentially leading to removing a file outside the container and affecting the host system. Successful exploitation of this issue may result in the arbitrary deletion of files and directories on the underlying host OS when building an image using a malicious Dockerfile or upstream image (for example, when using FROM).
Do not use BuildKit frontends or Dockerfiles from untrusted sources.
bugzilla.redhat.com/show_bug.cgi?id=2262225
github.com/moby/buildkit/pull/4603
github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8
nvd.nist.gov/vuln/detail/CVE-2024-23652
snyk.io/blog/cve-2024-23652-buildkit-build-time-container-teardown-arbitrary-delete/
www.cve.org/CVERecord?id=CVE-2024-23652