CVE-2024-23653
CVE-2024-23653 is a critical-severity vulnerability in Mobyproject Buildkit with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-863.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 3% (86th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-0453
- Weakness: CWE-863
- Affected product: Mobyproject Buildkit
- Published:
- Last modified:
Description
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit frontends from untrusted sources.
Frequently asked questions
- What is CVE-2024-23653?
- BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit frontends from untrusted sources.
- How severe is CVE-2024-23653?
- CVE-2024-23653 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2024-23653 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (86th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-23653?
- CVE-2024-23653 affects Mobyproject Buildkit. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-23653?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2024-23653 have an EU (EUVD) identifier?
- Yes. CVE-2024-23653 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-0453.
- When was CVE-2024-23653 published?
- CVE-2024-23653 was published on 2024-01-31 and last updated on 2026-06-17.
References
- https://github.com/moby/buildkit/pull/4602
- https://github.com/moby/buildkit/releases/tag/v0.12.5
- https://github.com/moby/buildkit/security/advisories/GHSA-wr6v-9f75-vh2g
Affected products (1)
- cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
More vulnerabilities in Mobyproject Buildkit
- CVE-2024-23652 — Critical (CVSS 10.0): BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.…
- CVE-2024-23651 — High (CVSS 8.7): BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.…
- CVE-2026-33747 — High (CVSS 8.4): BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.…
- CVE-2026-15793 — High (CVSS 7.5): BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git…
- CVE-2026-15792 — High (CVSS 7.5): A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
- CVE-2026-15791 — High (CVSS 7.5): A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The…
All CVEs affecting Mobyproject Buildkit →
Other CWE-863 (Incorrect Authorization) vulnerabilities
- CVE-2026-69555 — Critical (CVSS 10.0): Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-71398 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-27302 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48449 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary…
- CVE-2026-48286 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization…
- CVE-2026-48303 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization…
Browse all CWE-863 (Incorrect Authorization) vulnerabilities →