Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-3727

Published: May 10, 2024Last modified: September 30, 2025

Description

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Severity score breakdown

ParameterValue
Base score8.3
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbuildahFixed (1.37.5-r0)
podmanFixed (5.2.5-r0)
skopeoUnknown (1.10.0-r2)
StreambuildahFixed (1.35.4-r0)
podmanFixed (5.0.3-r0)
skopeoFixed (1.15.1-r0)

References

ON THIS PAGE