CVE-2024-3727

Updated on 14 May 2024

Severity

8.3 High severity

Details

CVSS score
8.3
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Overview

About vulnerability

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Details

Affected product:
AlmaLinux 9.2 ESU
Affected packages:
podman @ 4.4.1 (+3 more)
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Fixes