#VU74150 Insufficiently protected credentials in BuildKit - CVE-2023-26054
Published: March 28, 2023
BuildKit
Moby project
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to BuildKit may expose sensitive information when the user sends a build request that contains a Git URL with credentials and the build creates a provenance attestation describing that build. A remote attacker can gain access to sensitive information.