Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-3727

Опубликовано: 14 мая 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-containers-imagefixed5.29.3-1package
golang-github-containers-imageno-dsabookwormpackage
golang-github-containers-imageno-dsabullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2274767

  • https://github.com/containers/image/pull/2403

EPSS

Процентиль: 65%
0.00475
Низкий

Связанные уязвимости

CVSS3: 8.3
ubuntu
почти 2 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
redhat
почти 2 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
nvd
почти 2 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
msrc
больше 1 года назад

Containers/image: digest type does not guarantee valid type

suse-cvrf
больше 1 года назад

Security update for podman

EPSS

Процентиль: 65%
0.00475
Низкий