PT-2022-26170 · Unknown · Knative.Dev/Func

Andrew-Su

+1

·

Published

2022-11-19

·

Updated

2023-03-14

·

CVE-2022-41939

CVSS v3.1

6.1

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions knative.dev/func versions prior to 1.8.1
Description The issue affects developers using malicious or compromised third-party buildpacks, potentially exposing their registry credentials or local docker socket to a malicious lifecycle container. This issue only affects users who are using function buildpacks from third-parties.
Recommendations For versions prior to 1.8.1, update to release 1.8.1 to resolve the issue. As a temporary workaround, consider pinning the builder image to a specific content-hash with a valid lifecycle image to mitigate the attack.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-41939
GHSA-5336-2G3F-9G3M

Affected Products

Knative.Dev/Func