Incorrect Authorization Affecting kaniko package, versions <1.20.1-r0
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CHAINGUARDLATEST-KANIKO-6241555
- published 10 Feb 2024
- disclosed 31 Jan 2024
Introduced: 31 Jan 2024
CVE-2024-23653 Open this link in a new tabHow to fix?
Upgrade Chainguard
kaniko
to version 1.20.1-r0 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kaniko
package and not the kaniko
package as distributed by Chainguard
.
See How to fix?
for Chainguard
relevant fixed versions and status.
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure
entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit frontends from untrusted sources.