CVE-2023-43116

HIGH

Buildkite Elastic CI - Privilege Escalation

Title source: llm
STIX 2.1

Description

A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change ownership of arbitrary directories via the PIPELINE_PATH variable in the fix-buildkite-agent-builds-permissions script.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0032
EPSS Percentile 24.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-59
Status published
Products (2)
buildkite/elastic-ci-stack-for-aws 0 - 6.7.0Go
buildkite/elastic_ci_stack < 5.22.5
Published Dec 22, 2023
Tracked Since Feb 18, 2026