Docker Compose, Path Traversal, CVE-2024-53110 (Critical)

Listen to this Post

Docker Compose fails to properly sanitize file paths specified within remote OCI artifact annotations. When processing an artifact, if the `com.docker.compose.extends` or `com.docker.compose.envfile` annotations are present, Compose uses their values to construct a local file path. It does this by directly joining the untrusted, attacker-controlled path from the annotation with the base path of its local cache directory. This path construction lacks neutralization of special elements such as “../”, a flaw known as a path traversal vulnerability. Consequently, an attacker can craft a malicious annotation containing a sequence like “../../../etc/passwd”. When Compose processes this, it resolves the path, escaping the intended cache directory boundary. This allows the attacker to define a file write operation to an arbitrary, user-writable location on the host filesystem. The file write is triggered even during seemingly safe, read-only Compose commands, because these commands must still fetch and process the remote artifact to display configuration or service status.
Platform: Docker Compose
Version: < v2.40.2
Vulnerability: Path Traversal
Severity: Critical
date: 2024

Prediction: 2024-12-15

What Undercode Say:

docker compose config
docker compose ps
find ~/.docker/compose -name ".yml"
cat /tmp/arbitrary_file_overwritten
{
"annotations": {
"com.docker.compose.extends": "../../../../tmp/exploit"
}
}

How Exploit:

Malicious OCI artifact with crafted annotations triggers arbitrary file write during compose config.

Protection from this CVE:

Update to v2.40.2.

Impact:

Arbitrary File Overwrite, System Compromise.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top