github.com/moby/buildkit is vulnerable to Improper Link Resolution Before File Access
56
Medium Risk
BuildKit's cache mount source= selector on Windows Container on Windows workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured daemon can point a junction outside the cache and have the daemon resolve it. This lets the build read arbitrary host files reachable to the BuildKit daemon process. The fix normalizes and validates junction targets so reads stay within the cache root.
You are affected if you are using a version that falls within the vulnerable range and you run a BuildKit daemon on a Windows Container on Windows (WCOW) worker that accepts builds from untrusted authors.
github.com/moby/buildkit is vulnerable to Improper Link Resolution Before File Access in versions 0.0.1 - 0.31.1.
Upgrade the github.com/moby/buildkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant