PT-2024-6569 · Docker · Docker

Michal Findra

·

Published

2024-08-01

·

Updated

2025-01-09

·

CVE-2024-7387

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: openshift/builder (affected versions not specified)
Description: A flaw was found in openshift/builder, allowing command injection via path traversal. This enables a malicious user to execute arbitrary commands on the OpenShift node running the builder container. When using the "Docker" strategy, executable files inside the privileged build container can be overridden using the spec.source.secrets.secret.destinationDir attribute of the BuildConfig definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2024-07713
CVE-2024-7387
GHSA-QQV8-PH7F-H3F7
GO-2024-3129

Affected Products

Docker