PT-2025-11542 · Buildkit+4 · Buildkit+4

Published

2025-03-17

·

Updated

2025-07-17

·

CVE-2025-0495

CVSS v4.0

4.1

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Buildx versions (affected versions not specified)
Description The issue concerns the Buildx Docker CLI plugin, which extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. However, when supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This does not impact secrets passed to the Github cache backend via environment variables or registry authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-58854
AZL-58863
BDU:2025-06572
CVE-2025-0495
GHSA-M4GQ-FM9H-8Q75
GO-2025-3527
OPENSUSE-SU-2025:14910-1
OPENSUSE-SU-2025:14980-1
OPENSUSE-SU-2025:14985-1
SUSE-SU-2025:02289-1
SUSE-SU-2025:02289-2
SUSE-SU-2025:1341-1
SUSE-SU-2025:1344-1
SUSE-SU-2025:20205-1
SUSE-SU-2025:20360-1
SUSE-SU-2025_02289-1
SUSE-SU-2025_02289-2
SUSE-SU-2025_1341-1
SUSE-SU-2025_1344-1

Affected Products

Buildkit
Buildx
Opentelemetry
Red Os
Suse