Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-3727

Опубликовано: 14 мая 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-containers-imagefixed5.29.3-1package
golang-github-containers-imageno-dsabookwormpackage
golang-github-containers-imageno-dsabullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2274767

  • https://github.com/containers/image/pull/2403

EPSS

Процентиль: 54%
0.00318
Низкий

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
redhat
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
nvd
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
msrc
7 месяцев назад

Описание отсутствует

suse-cvrf
11 месяцев назад

Security update for podman

EPSS

Процентиль: 54%
0.00318
Низкий