VDB
BDU%3A2023-03675
BDU%3A2023-03675
PUBLISHED
CVSS 4 MEDIUM
Уязвимость приложения для упрощения и стандартизации распространения содержимого контейнеров Open Container Initiative Distribution Specification (OCI Distribution Specification), связанная с ошибкой смешения типов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
Risk Scores
CVSS 2.0
4
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Fedora Project, ООО «Ред Софт», АО «ИВК», IBM Corp., Сообщество свободного программного обеспечения, Cloud Native Computing Foundation, Moby Project | Red Hat Enterprise Linux, Fedora, РЕД ОС (запись в едином реестре российских программ №3751), Альт 8 СП (запись в едином реестре российских программ №4305), Red Hat OpenShift Container Platform, Red Hat Advanced Cluster Security (RHACS) for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes, IBM CICS TX Advanced, Red Hat Migration Toolkit for Containers, Podman, Open Container Initiative Distribution Specification, OCI Image Format Specification, Containerd, Moby |
Timeline
- Jul 13, 2023 CVE Published
- Aug 8, 2023 CVE Updated
References
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-podman-cve-2023-0778-cve-2022-27649-cve-2021-41190-cve-2021-4024-cve-2022/ url
- https://www.ibm.com/support/pages/security-bulletin-ibm-cics-tx-advanced-vulnerable-open-container-initiative-distribution-specification-vulnerability-cve-2021-41190 url
- https://access.redhat.com/security/cve/cve-2021-41190 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4334HT7AZPLWNYHW4ARU6JBUF3VZJPZN/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A2RRFNTMFYKOTRKD37F5ANMCIO3GGJML/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DX63GRWFEI5RVMYV6XLMCG4OHPWZML27/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4OJ764CKKCWCVONHD4YXTGR7HZ7LRUV/ url
- https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m url
- https://github.com/opencontainers/image-spec/security/advisories/GHSA-77vh-xpmg-72qh url
- https://www.openwall.com/lists/oss-security/2021/11/19/10 url
- https://security-tracker.debian.org/tracker/CVE-2021-41190 url
- https://github.com/moby/moby/pull/43025/files url
- https://github.com/moby/moby/security/advisories/GHSA-xmmx-7jpf-fx42 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2024938 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://github.com/opencontainers/distribution-spec/commit/ac28cac0557bcd3084714ab09f9f2356fe504923 advisory
- https://github.com/opencontainers/distribution-spec/releases/tag/v1.0.1 advisory
- https://github.com/opencontainers/image-spec/releases/tag/v1.0.2 advisory
- https://github.com/containers/podman/releases/tag/v3.4.3 advisory
- https://github.com/containerd/containerd/releases/tag/v1.4.12 advisory
…and 6 more