GHSA-7236-3392-c5c6
Dashboard / Vulnerabilities / GHSA-7236-3392-c5c6
GHSA-7236-3392-c5c6
Summary: BuildKit: Custom frontend could bypass Seccomp/AppArmor
Details: ### Impact A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the `security.insecure` entitlement. Other security measures, like Linux capabilities were still applied to these containers. ### Patches Problem has been fixed in versions v0.31.1+ ### Workarounds Only use BuildKit frontends from trusted providers.
References: https://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6, https://github.com/moby/buildkit
Affected packages
Package
Name: github.com/moby/buildkit
Purl: pkg:golang/github.com/moby/buildkit
Affected ranges
Type: SEMVER
Events:
