Listen to this Post
Docker Compose fails to properly sanitize file paths specified within remote OCI artifact annotations. When processing an artifact, if the `com.docker.compose.extends` or `com.docker.compose.envfile` annotations are present, Compose uses their values to construct a local file path. It does this by directly joining the untrusted, attacker-controlled path from the annotation with the base path of its local cache directory. This path construction lacks neutralization of special elements such as “../”, a flaw known as a path traversal vulnerability. Consequently, an attacker can craft a malicious annotation containing a sequence like “../../../etc/passwd”. When Compose processes this, it resolves the path, escaping the intended cache directory boundary. This allows the attacker to define a file write operation to an arbitrary, user-writable location on the host filesystem. The file write is triggered even during seemingly safe, read-only Compose commands, because these commands must still fetch and process the remote artifact to display configuration or service status.
Platform: Docker Compose
Version: < v2.40.2
Vulnerability: Path Traversal
Severity: Critical
date: 2024
Prediction: 2024-12-15
What Undercode Say:
docker compose config docker compose ps find ~/.docker/compose -name ".yml" cat /tmp/arbitrary_file_overwritten
{
"annotations": {
"com.docker.compose.extends": "../../../../tmp/exploit"
}
}
How Exploit:
Malicious OCI artifact with crafted annotations triggers arbitrary file write during compose config.
Protection from this CVE:
Update to v2.40.2.
Impact:
Arbitrary File Overwrite, System Compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

