Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-3727

Опубликовано: 09 мая 2024
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Отчет

Some conditions are necessary for this attack to occur, such as the attacker being able to upload malicious images to the registry and persuade a victim to pull them. Hence, the severity of this flaw was rated as Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/agent-service-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-agent-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-reporter-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/hive-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-clientsWill not fix
OpenShift Source-to-Image (S2I)source-to-image-containerAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=2274767containers/image: digest type does not guarantee valid type

EPSS

Процентиль: 54%
0.00318
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
nvd
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CVSS3: 8.3
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 8.3
debian
около 1 года назад

A flaw was found in the github.com/containers/image library. This flaw ...

suse-cvrf
11 месяцев назад

Security update for podman

EPSS

Процентиль: 54%
0.00318
Низкий

8.3 High

CVSS3

Уязвимость CVE-2024-3727