GHSA-xw73-rw38-6vjc
Classic builder cache poisoning
Quick fix
GHSA-xw73-rw38-6vjc — github.com/docker/docker: upgrade to the fixed version with the command below.
go get github.com/docker/docker@v24.0.9Details
The classic builder cache system is prone to cache poisoning if the image is built `FROM scratch`. Also, changes to some instructions (most important being `HEALTHCHECK` and `ONBUILD`) would not cause a cache miss.
An attacker with the knowledge of the Dockerfile someone is using could poison their cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps.
For example, an attacker could create an image that is considered as a valid cache candidate for: ``` FROM scratch MAINTAINER Pawel ```
when in fact the malicious image used as a cache would be an image built from a different Dockerfile.
In the second case, the attacker could for example substitute a different `HEALTCHECK` command.
### Impact
23.0+ users are only affected if they explicitly opted out of Buildkit (`DOCKER_BUILDKIT=0` environment variable) or are using the `/build` API endpoint (which uses the classic builder by default).
All users on versions older than 23.0 could be impacted. An example could be a CI with a shared cache, or just a regular Docker user pulling a malicious image due to misspelling/typosquatting.
Image build API endpoint (`/build`) and `ImageBuild` function from `github.com/docker/docker/client` is also affected as it the uses classic builder by default.
### Patches
Patches are included in Moby releases:
- v25.0.2 - v24.0.9 - v23.0.10
### Workarounds
- Use `--no-cache` or use Buildkit if possible (`DOCKER_BUILDKIT=1`, it's default on 23.0+ assuming that the buildx plugin is installed). - Use `Version = types.BuilderBuildKit` or `NoCache = true` in `ImageBuildOptions` for `ImageBuild` call.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 24.0.9go get github.com/docker/docker@v24.0.925.0.0Fixed in: 25.0.2go get github.com/docker/docker@v25.0.2References
- https://github.com/moby/moby/security/advisories/GHSA-xw73-rw38-6vjc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-24557[ADVISORY]
- https://github.com/moby/moby/commit/3e230cfdcc989dc524882f6579f9e0dac77400ae[WEB]
- https://github.com/moby/moby/commit/fca702de7f71362c8d103073c7e4a1d0a467fadd[WEB]
- https://github.com/moby/moby/commit/fce6e0ca9bc000888de3daa157af14fa41fcd0ff[WEB]
- https://github.com/moby/moby[PACKAGE]