CVE-2024-24557
Classic builder cache poisoning in github.com/docker/docker
描述
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the knowledge of the Dockerfile someone is using could poison their cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps. 23.0+ users are only affected if they explicitly opted out of Buildkit (DOCKER_BUILDKIT=0 environment variable) or are using the /build API endpoint. All users on versions older than 23.0 could be impacted. Image build API endpoint (/build) and ImageBuild function from github.com/docker/docker/client is also affected as it the uses classic builder by default. Patches are included in 24.0.9 and 25.0.2 releases.
如何修補 CVE-2024-24557
要修補 CVE-2024-24557,請將受影響套件升級到下列已修補版本。
- —未列出修補版本
- —升級至 24.0.9 或更新版本
- —升級至 24.0.9+incompatible 或更新版本
- —升級至 24.0.9 或更新版本
- —升級至 24.0.9+incompatible 或更新版本
CVE-2024-24557 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0
- from 0, < 24.0.9
- from 0, < 24.0.9+incompatible, >= 25.0.0+incompatible, < 25.0.2+incompatible
- from 0, < 24.0.9
- from 0, < 24.0.9+incompatible, >= 25.0.0+incompatible, < 25.0.2+incompatible
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.9 | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L |