CVE-2024-23651 is a race condition vulnerability in BuildKit (mobyproject buildkit) that allows malicious build steps to access files from the host system. This high-severity flaw (CVSS 7.4) has a network attack vector and high attack complexity, potentially leading to unauthorized host system access. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating heightened awareness. Organizations are advised to update to BuildKit v0.12.5 or implement workarounds to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.5CPE matchmatch criteria | cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-23651
Jun 11, 2024BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts
Jan 31, 2024moby/buildkit: possible race condition with accessing subpaths from cache mounts
Jan 31, 2024BuildKit possible race condition with accessing subpaths from cache mounts
Jan 9, 2024