CVE-2024-23650

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 31, 2024
Updated: Feb 9, 2024
CWE ID 754

Summary

CVE-2024-23650 is a vulnerability affecting BuildKit, a toolkit used for converting source code into build artifacts. Malicious BuildKit clients or frontends can craft requests that cause the daemon to crash with a panic. This issue has been addressed in version 0.12.5. As a temporary measure, users are advised to avoid utilizing untrusted BuildKit frontends.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share