CVE-2024-23653 is a critical vulnerability affecting BuildKit, a toolkit used for building container images. It allows an attacker to exploit BuildKit's interactive container APIs to run containers with elevated privileges, even when such operations are normally restricted by security configurations. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk. It has a network attack vector with low complexity, requiring no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability of the affected system. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation. It is part of a set of "Leaky Vessels" vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.5CPE matchmatch criteria | cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-23653
Jun 11, 2024Buildkit's interactive containers API does not validate entitlements check
Jan 31, 2024moby/buildkit: Buildkit's interactive containers API does not validate entitlements check
Jan 31, 2024BuildKit interactive containers API does not validate entitlements check
Jan 9, 2024