Insufficiently protected credentials in BuildKit - CVE-2023-26054
Published: March 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to BuildKit may expose sensitive information when the user sends a build request that contains a Git URL with credentials and the build creates a provenance attestation describing that build. A remote attacker can gain access to sensitive information.
Affected software
Gentoo Linux
Anolis OS
Fedora
OpenShift Service Mesh
moby
Red Hat OpenShift Container Platform
buildkit
buildkit-doc
moby-engine
app-containers/docker
How to mitigate CVE-2023-26054
OpenShift Service Mesh - update to 2.4.4
Red Hat OpenShift Container Platform - update to 4.13.3
moby - update to 23.0.2
buildkit - update to 0.13.2-1
buildkit-doc - update to 0.13.2-1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
app-containers/docker - update to 25.0.4
External References
Related Security Bulletins
- Credentials exposure in BuildKit
- moby update for buildkit
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Fedora 39 update for moby-engine
- Fedora 37 update for moby-engine
- Fedora 38 update for moby-engine
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh for 2.4
- Gentoo update for Docker
- Anolis OS update for buildkit