PT-2022-26170 · Unknown · Knative.Dev/Func
Andrew-Su
+1
·
Published
2022-11-19
·
Updated
2023-03-14
·
CVE-2022-41939
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
knative.dev/func versions prior to 1.8.1
Description
The issue affects developers using malicious or compromised third-party buildpacks, potentially exposing their registry credentials or local docker socket to a malicious
lifecycle container. This issue only affects users who are using function buildpacks from third-parties.Recommendations
For versions prior to 1.8.1, update to release 1.8.1 to resolve the issue. As a temporary workaround, consider pinning the builder image to a specific content-hash with a valid
lifecycle image to mitigate the attack.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knative.Dev/Func