QID 997069

Date Published: 2024-02-02

QID 997069: GO (Go) Security Update for github.com/moby/moby (GHSA-xw73-rw38-6vjc)

The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-xw73-rw38-6vjc for updates and patch information.
    Vendor References

    CVEs related to QID 997069

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xw73-rw38-6vjc github.com/moby/moby URL Logo github.com/advisories/GHSA-xw73-rw38-6vjc