CVE-2024-23653
Privilege escalation in github.com/moby/buildkit
9.8
CRITICAL
CVSS 3.1
EPSS 3.0%
描述
BuildKit provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request.
如何修補 CVE-2024-23653
要修補 CVE-2024-23653,請將受影響套件升級到下列已修補版本。
- —升級至 0.12.5 或更新版本
- —升級至 0.12.5 或更新版本
CVE-2024-23653 正在被利用嗎?
低 — EPSS 為 3.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.12.5
- from 0, < 0.12.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |