CVE-2024-3727

high

Description

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

References

https://lists.fedoraproject.org/archives/list/[email protected]/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN/

https://lists.fedoraproject.org/archives/list/[email protected]/message/QFXMF3VVKIZN7ZMB7PKZCSWV6MOMTGMQ/

https://lists.fedoraproject.org/archives/list/[email protected]/message/GD2GSBQTBLYADASUBHHZV2CZPTSLIPQJ/

https://lists.fedoraproject.org/archives/list/[email protected]/message/FBZQ2ZRMFEUQ35235B2HWPSXGDCBZHFV/

https://lists.fedoraproject.org/archives/list/[email protected]/message/DTOMYERG5ND4QFDHC4ZSGCED3T3ESRSC/

https://lists.fedoraproject.org/archives/list/[email protected]/message/DLND3YDQQRWVRIUPL2G5UKXP5L3VSBBT/

https://lists.fedoraproject.org/archives/list/[email protected]/message/CYT3D2P3OJKISNFKOOHGY6HCUCQZYAVR/

https://lists.fedoraproject.org/archives/list/[email protected]/message/6B37TXOKTKDBE2V26X2NSP7JKNMZOFVP/

https://lists.fedoraproject.org/archives/list/[email protected]/message/4HEYS34N55G7NOQZKNEXZKQVNDGEICCD/

https://bugzilla.redhat.com/show_bug.cgi?id=2274767

https://access.redhat.com/security/cve/CVE-2024-3727

https://access.redhat.com/errata/RHSA-2024:9960

https://access.redhat.com/errata/RHSA-2024:9102

https://access.redhat.com/errata/RHSA-2024:9098

https://access.redhat.com/errata/RHSA-2024:9097

https://access.redhat.com/errata/RHSA-2024:8425

https://access.redhat.com/errata/RHSA-2024:8260

https://access.redhat.com/errata/RHSA-2024:7941

https://access.redhat.com/errata/RHSA-2024:7922

https://access.redhat.com/errata/RHSA-2024:7187

https://access.redhat.com/errata/RHSA-2024:7182

https://access.redhat.com/errata/RHSA-2024:7174

https://access.redhat.com/errata/RHSA-2024:7164

https://access.redhat.com/errata/RHSA-2024:6824

https://access.redhat.com/errata/RHSA-2024:6708

https://access.redhat.com/errata/RHSA-2024:6054

https://access.redhat.com/errata/RHSA-2024:5951

https://access.redhat.com/errata/RHSA-2024:5258

https://access.redhat.com/errata/RHSA-2024:4960

https://access.redhat.com/errata/RHSA-2024:4850

https://access.redhat.com/errata/RHSA-2024:4613

https://access.redhat.com/errata/RHSA-2024:4159

https://access.redhat.com/errata/RHSA-2024:3718

https://access.redhat.com/errata/RHSA-2024:0045

Details

Source: Mitre, NVD

Published: 2024-05-14

Updated: 2024-11-23

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Severity: High