CVE-2024-24557 is a cache poisoning vulnerability affecting Moby, the open-source containerization project by Docker. Specifically, the classic builder cache system can be poisoned if an image is built FROM scratch, or if certain instructions like HEALTHCHECK or ONBUILD are changed without triggering a cache miss. This allows an attacker, with knowledge of a Dockerfile, to craft a malicious image that is considered a valid cache candidate for build steps. The vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. Users of Moby versions older than 23.0 are fully impacted, while 23.0+ users are only affected if they explicitly opt out of Buildkit or use the /build API endpoint. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there is limited community discussion and media coverage, patches are available in Moby versions 24.0.9 and 25.0.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.0.9CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* | ||
>= 25.0.0, < 25.0.2CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - October 2024
Oct 14, 2024CVE-2024-24557
Jun 11, 2024AS-2024-001: Docker Engine
Mar 13, 2024Moby classic builder cache poisoning
Feb 13, 2024Classic builder cache poisoning
Feb 1, 2024moby: classic builder cache poisoning
Feb 1, 2024