Docker Buildx Bake 在处理某些文件系统输入时,未请求预期的 fs.read 权限审批。不受信任的 Bake 定义可能通过无路径的 secret(其 ID 被解释为客户端路径名)暴露一个可读文件;或者在 entitlement 验证检查了不同的路径表示后,消耗项目外部的本地 OCI 镜像布局。运行不受信任的 Bake 定义的用户会受到影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Docker | Docker Buildx | 0 ~ 0.37.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet