CVE-2024-23650 is a medium-severity vulnerability affecting Moby Project BuildKit, a toolkit for converting source code to build artifacts. A malicious client or frontend can craft a request that causes the BuildKit daemon to crash, leading to a denial of service. The vulnerability has a CVSS score of 5.3 and is rated as low impact for availability. While no active exploitation or public exploit code has been identified, the issue is resolved in BuildKit v0.12.5, and users should update or avoid untrusted BuildKit frontends.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.5CPE matchmatch criteria | cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
BuildKit vulnerable to possible panic when incorrect parameters sent from frontend
Jan 31, 2024moby/buildkit: Possible race condition with accessing subpaths from cache mounts
Jan 31, 2024BuildKit possible panic when incorrect parameters sent from frontend
Jan 9, 2024