Impact
BuildKit custom frontends or clients using the raw low-level API can set
git.checkoutbundle=true when checking out Git sources. If the Git source is
malicious, this could lead to a crafted command invocation on the host.
Patches
The issue has been fixed in v0.31.2+.
Workarounds
The issue requires using a custom frontend together with a malicious Git source. Current Dockerfile builds are not affected.
References
Credits
This issue was reported by Zhibin Hu and Lei Wang of HuaweiCloud
Impact
BuildKit custom frontends or clients using the raw low-level API can set
git.checkoutbundle=truewhen checking out Git sources. If the Git source ismalicious, this could lead to a crafted command invocation on the host.
Patches
The issue has been fixed in v0.31.2+.
Workarounds
The issue requires using a custom frontend together with a malicious Git source. Current Dockerfile builds are not affected.
References
Credits
This issue was reported by Zhibin Hu and Lei Wang of HuaweiCloud