github.com/moby/buildkit is vulnerable to Path Traversal
35
Low Risk
A file operation in BuildKit's low-level build API resolves deletion paths without confining them to the build container rootfs. A crafted LLB message can make the delete action escape into the real host temporary directory. This allows removal of the contents of the host /tmp directory. The fix constrains the operation to the intended rootfs path.
You are affected if you are using a version that falls within the vulnerable range and you allow untrusted parties to issue builds through a custom frontend that uses the low-level build API.
github.com/moby/buildkit is vulnerable to Path Traversal in versions 0.10.0 - 0.31.1.
Upgrade the github.com/moby/buildkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant