CVE-2024-3727High· 8.3▾ TwilightA flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.3%
Last analysed / modified upstream
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/containers/image < 5.30.1github.com/containers/image/v5 >= 5.30.0, < 5.30.1github.com/containers/image/v5 < 5.29.3Patched in:
github.com/containers/image 5.30.1github.com/containers/image/v5 5.30.1github.com/containers/image/v5 5.29.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1753High· 8.6Podman affected by CVE-2024-1753 container escape at build time
CVE-2022-1227High· 8.8Podman publishes a malicious image to public registries
CVE-2024-9341Medium· 5.4A flaw was found in Go
CVE-2022-27649High· 7.5Podman's default inheritable capabilities for linux container not empty
CVE-2022-27651Medium· 6.8Non-empty default inheritable capabilities for linux container in Buildah
CVE-2021-3602Medium· 5.5Buildah processes using chroot isolation may leak environment values to intermediate processes