Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39592
HistoryMar 08, 2023 - 11:33 a.m.

Information Disclosure

2023-03-0811:33:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
vulnerability buildkit access repositories

0.001 Low

EPSS

Percentile

50.4%

github.com/moby/buildkit is vulnerable to Information Disclosure. When a build request contains a Git URL with credentials, anyone with access to the build provenance attestation will be able to view the credentials issued. An attacker can use these Git credentials to access repositories.