Home / Companies / Snyk / Blog / January 2024

January 2024 Summaries

16 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
The Leaky Vessels vulnerabilities, identified by Snyk's Security Labs team, are four container escape vulnerabilities in core container infrastructure components that allow unauthorized access to the underlying host operating system. An attacker could use these container escapes to gain access to sensitive data and launch further attacks. The vulnerabilities were disclosed responsibly by Snyk, with Docker and other vendors subsequently releasing patches. To mitigate these vulnerabilities, users should upgrade their systems running container engines and build tools as soon as fixes are released by their providers. Two open source tools, leaky-vessels-runtime-detector and leaky-vessels-static-detector, have been released to aid in exploit detection. The Snyk Security Labs team has extensive experience with responsible disclosure of vulnerabilities across various ecosystems, and users can reach out to them for assistance if they find a potential vulnerability.
Jan 31, 2024 1,729 words in the original blog post.
The runc process.cwd and leaked fds container breakout vulnerability (CVE-2024-21626) affects all versions of runc <=1.1.11, used by Docker engine and other containerization technologies such as Kubernetes. Exploitation can result in container escape to the underlying host OS, potentially executing malicious code or accessing sensitive files. The vulnerability occurs due to a flaw in the order of operations when applying the WORKDIR directive defined in the Dockerfile. runc has mitigated this issue by ensuring the directory specified in the WORKDIR directive is present in the container root filesystem and implementing additional hardening steps. Snyk recommends taking immediate action, updating to runc 1.1.12 or later, and following vendor advisories to mitigate this security vulnerability. Organizations can use Snyk's tools for runtime detection and static analysis to evaluate their risk or exposure, although these tools cannot prevent exploitation.
Jan 31, 2024 1,114 words in the original blog post.
The Docker Buildkit has a vulnerability (CVE-2024-23653) that allows an attacker to escape from a container and achieve full host root command execution when building an image using a malicious Dockerfile or upstream image. This vulnerability occurs due to a missing privilege check in the GRPC endpoint, which can be exploited by launching an elevated privilege container during build time. To mitigate this issue, Buildkit has been patched in version v0.12.5 and users are advised to update their instances of Buildkit to this version or later. Additionally, Snyk has developed two tools to detect this vulnerability: a runtime detection tool using eBPF-based instrumentation and a static analysis detector that analyzes Dockerfiles and flags potential exploit attempts. It is recommended to update container infrastructure as soon as possible and consider using these tools for evaluation of risk or exposure when updating is not immediately possible.
Jan 31, 2024 946 words in the original blog post.
The vulnerability CVE-2024-23651 in Docker Buildkit allows a malicious container to escape the underlying host OS by exploiting a time-of-check/time-of-use (TOCTOU) race condition when mounting a cache volume at container build time. This can lead to full host root command execution if the Docker engine is running as the root user. To mitigate this vulnerability, Snyk recommends updating Buildkit to version v0.12.5 or later and using tools such as the eBPF-based runtime detection tool or static analysis detector to detect potential exploit attempts. Organizations should also consider updating their container infrastructure provider to ensure that it has been patched. Additionally, using well-maintained parent images from trusted sources and staying up-to-date with the latest versions is a good best practice.
Jan 31, 2024 1,022 words in the original blog post.
A critical vulnerability (CVE-2024-23652) has been discovered in all versions of Docker Buildkit <=v0.12.4, which can result in arbitrary file and directory deletion on the underlying host OS when building an image using a malicious Dockerfile or upstream image. This vulnerability allows for exploitation by an attacker to delete any file in the host filesystem due to Buildkit's root privileges. To mitigate this issue, it is recommended to update Buildkit to version v0.12.5 or later and to use tools such as Snyk's runtime detection tool (leaky-vessels-runtime-detector) or static analysis detector (leaky-vessels-static-detector) for early detection of vulnerable containers. Organizations should also take precautions by using well-maintained parent images, clearing out build caches, and verifying the provenance of parent images to prevent exploitation.
Jan 31, 2024 879 words in the original blog post.
There are various ways bug bounty hunting can be approached, including vulnerability disclosure programs and bug bounty programs, each with its own advantages and disadvantages. Successful bug hunters need to find their niche, stay consistent in their efforts, collaborate with others, automate tasks where possible, challenge themselves outside of their comfort zone, and take breaks when needed. They should also prioritize learning new techniques and technologies to stay ahead in the field. By following these tips, individuals can increase their chances of becoming successful bug bounty hunters.
Jan 25, 2024 1,246 words in the original blog post.
The DevSecOps methodology integrates security into a continuous integration, continuous delivery, and continuous deployment pipeline, incorporating phases such as planning, development, testing, release and deliver, deploy, operate, scanning, validating, and monitoring code throughout the software development lifecycle. The best DevSecOps tools should integrate seamlessly into a DevOps workflow, offering comprehensive testing and monitoring, tight feedback loops, and support for unique DevSecOps objectives. Key tools include Software Composition Analysis (SCA) to detect open source vulnerabilities, Static Application Security Testing (SAST) to identify coding flaws, Dynamic Application Security Testing (DAST) to scan running applications, Container security tools to evaluate dependencies, Infrastructure as Code (IaC) scanning tools to flag misconfigurations, Cloud security tools to address cloud-based vulnerabilities, and Automated testing tools to catch defects in the development process. Adopting a DevSecOps mindset is crucial for building a secure, efficient production pipeline, and choosing the right tools can help teams quickly and efficiently secure their workflow.
Jan 23, 2024 1,583 words in the original blog post.
In recent years, advancements in generative AI have reshaped the tech landscape and raised concerns about its impact on software development cycles and overall security of business applications. Experts from Snyk and Dynatrace emphasized the importance of cross-team governance, devising thorough strategies for testing and implementing new technology, and maintaining focus on security throughout development. They also stressed the need to prioritize AI governance, take a cautious approach when introducing new technologies, gauge explainability and transparency in chosen tools, put code security in place, and balance AI opportunity and risk, especially in development. By following these tips, developers can leverage AI securely without compromising security.
Jan 22, 2024 905 words in the original blog post.
The Jinja2 XSS vulnerability (CVE-2024-22195) is a cross-site scripting issue that affects all versions prior to 3.1.3 due to the xmlattr filter in Jinja2 when keys containing spaces are used, based on user input, allowing attackers to inject arbitrary HTML attributes into templates and potentially execute untrusted scripts in a user's browser. Developers can check if their project is using a vulnerable version of Jinja2 by looking at the requirements.txt file or running pip list | grep Jinja2 in their project's virtual environment. Upgrading to Jinja2 version 3.1.3 immediately is recommended to address this vulnerability, and tools like Snyk can be used for ongoing vulnerability monitoring and scanning containerized applications with Docker that bundle this vulnerable dependency. Developers should also follow general security best practices such as validating and sanitizing all user inputs, implementing content security policies, and conducting regular security audits.
Jan 18, 2024 1,059 words in the original blog post.
Transforming the lessons learned in 2023 into new learning in 2024 will be an exciting journey, marked by a surge in AI usage, including cyberattacks utilizing AI and machine learning. Application security posture management (ASPM) has gained increased awareness, with Snyk launching its own ASPM solution called Snyk AppRisk to help appsec teams implement, manage, and scale their security programs. Security experts have shared personal and professional New Year's security resolutions for 2024, focusing on improving personal OpSec, managing secrets, staying ahead of emerging technologies like AI, and prioritizing mental health for security teams. Resolutions include adopting AI-driven security solutions, investing in cutting-edge cybersecurity companies, delivering cybersecurity awareness training through gamification, and championing reproducible builds to ensure the integrity of produced artifacts.
Jan 18, 2024 1,188 words in the original blog post.
Snyk has announced its partnership with Helios, integrating Helios' runtime application security capabilities into Snyk AppRisk to provide cloud-to-code visibility into application risk, empowering security teams to manage and scale their AppSec programs. Conventional security testing approaches focus on statically analyzing source code during development and build time, but runtime context offers a real-world perspective into the application's behavior, providing a more accurate assessment of application risk. The integration will enable Snyk customers to discover app assets throughout their software supply chain, prioritize issues using holistic application context, and ensure all assets are covered and secured by appropriate controls. With this partnership, Snyk aims to provide an industry-first comprehensive perspective of application risk spanning the entire software development lifecycle, from code to cloud.
Jan 16, 2024 874 words in the original blog post.
Virtual environments are self-contained directories that contain a Python installation for a particular version of Python, plus additional packages. They help separate project-specific dependencies by creating isolated spaces, ensuring each project has its own set of dependencies without conflicts with other projects. Virtual environments allow developers to work on multiple Python projects without worrying about interdependencies and provide an isolated space where they can install Python and other packages, making their projects reproducible. There are several tools available for creating virtual environments, including venv, virtualenv, and pipenv. Venv is a built-in Python module that creates virtual environments, which are essential for isolating project-specific dependencies and maintaining clean development ecosystems. Docker containers also provide consistency, isolation, and reproducibility in development, making them beneficial for Python development. Snyk is a tool that helps find and fix security vulnerabilities in Docker images, ensuring they are secure before deployment.
Jan 10, 2024 1,589 words in the original blog post.
Choosing a security tool for AI-generated code requires careful consideration to balance the needs of security teams and developers. A good security tool should allow developers to work seamlessly while securing applications reliably, without interrupting their workflow. It should also be accurate and avoid "AI hallucinations" by leveraging expert knowledge and machine learning methods. Additionally, it should perform thorough interfile analysis, providing a comprehensive view of the application's structure and functions. Automated reporting capabilities are essential for security leaders to track progress and assess overall risk. Finally, the tool should be independent and able to evolve with changing needs, allowing developers to choose their preferred AI coding tools.
Jan 09, 2024 1,774 words in the original blog post.
The Node.js security scanning API is built on the powerful combination of Platformatic Cloud and Fastify, a modern web framework for Node.js. The API leverages Snyk to test npm packages for known security vulnerabilities, providing developers with a robust tool to enhance their application's security. By deploying the API to Platformatic Cloud, developers can make it accessible on the Internet while maintaining control over its configuration and security settings. The platform also includes features like automatic deployment, monitoring, and security scanning, making it an ideal choice for hosting Node.js applications.
Jan 05, 2024 2,980 words in the original blog post.
The Struts CVE-2023-50164 is a path traversal vulnerability that can lead to arbitrary code execution, similar to the infamous 2017 Equifax breach. This new vulnerability allows attackers to upload files and "break out" of the designated upload folder by giving a relative path, which can lead to remote code execution. Upgrading Struts to version 2.5.33 or 6.3.0.2 (or greater) is recommended for remediation. A proof-of-concept exploit demonstrates how this vulnerability works and highlights the importance of securing Struts. Snyk's scanning tools can help detect this issue in both dependencies and custom code, providing actionable advice for remediation. The updated version of Struts automatically sanitizes paths provided as input, making it more secure against path traversal attacks. Using Snyk to actively monitor projects can boost productivity by automatically notifying developers of new vulnerabilities and creating pull requests for review and merge.
Jan 02, 2024 1,667 words in the original blog post.
Kroger, a large retail giant with 2,700 stores and 400,000 employees, faces unique challenges in securing its digital supply chain due to its massive scale. To address these challenges, Kroger has implemented a shift-left approach using the full Snyk platform, integrating security practices early in the software development life cycle. This approach allows Kroger to navigate its diverse technology stack efficiently and mitigate risk proactively. The company uses Snyk Code for cross-cutting visibility into issues and to take a proactive stance on security, leveraging tools like Snyk to maximize efficiency despite its vast scale. Kroger's goal is to balance security measures with developer autonomy, ensuring the codebase is rock-solid while allowing developers to experiment with new packages. The company has successfully automated the generation of Software Bill of Materials (SBOMs) and is exploring their practical applications beyond vulnerability identification, including AI governance and compliance.
Jan 02, 2024 888 words in the original blog post.