Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-3727

Published: May 10, 2024Last modified: May 28, 2025

Description

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Severity score breakdown

ParameterValue
Base score8.3
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbuildahUnknown (1.28.0-r1)
podmanUnknown (4.3.1-r0)
skopeoUnknown (1.10.0-r2)
StreambuildahUnknown (1.31.0-r0)
podmanUnknown (4.5.1-r1)
skopeoUnknown (1.13.0-r1)

References

ON THIS PAGE