Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6wvf-f2vw-3425

Опубликовано: 14 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.3

Описание

github.com/containers/image allows unexpected authenticated registry accesses

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Ссылки

Пакеты

Наименование

github.com/containers/image

go
Затронутые версииВерсия исправления

< 5.30.1

5.30.1

Наименование

github.com/containers/image/v5

go
Затронутые версииВерсия исправления

>= 5.30.0, < 5.30.1

5.30.1

Наименование

github.com/containers/image/v5

go
Затронутые версииВерсия исправления

< 5.29.3

5.29.3

EPSS

Процентиль: 54%
0.00318
Низкий

8.3 High

CVSS3

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
redhat
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
nvd
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 8.3
debian
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw ...

EPSS

Процентиль: 54%
0.00318
Низкий

8.3 High

CVSS3

Дефекты

CWE-354