github.com/moby/buildkit is vulnerable to Security Feature Bypass
35
Low Risk
BuildKit applies Seccomp and AppArmor confinement to build containers based on the build request. A custom frontend can send a crafted request that disables Seccomp and AppArmor for the build container without the user granting the security.insecure entitlement. Other controls such as Linux capabilities still apply, but the intended sandboxing is weakened. The fix enforces these protections regardless of the crafted request.
You are affected if you are using a version that falls within the vulnerable range and you allow untrusted parties to supply custom BuildKit frontends.
github.com/moby/buildkit is vulnerable to Security Feature Bypass in versions 0.0.1 - 0.31.0.
Upgrade the github.com/moby/buildkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant