VDB
RHSA-2024%3A6054
RHSA-2024%3A6054
PUBLISHED
CVSS 8.300000190734863 HIGH
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:0b590586a0bfc3d6399505dfb5ca1367c232d0b13245fd3ab9b0e5ac24a0b5a2_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-rhel8-operator@sha256:0b590586a0bfc3d6399505dfb5ca1367c232d0b13245fd3ab9b0e5ac24a0b5a2_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:6f78b7cbdee3e6c08c6ebcdf67dc2c49dd93bba1fa0bcbc42154bbd6bd6b60f3_ppc64le as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-main-rhel8@sha256:9a11dad9b17cc9c4f13ab85d920ac3b0796221457ca4894fc6578f92b022880e_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-main-rhel8@sha256:9a11dad9b17cc9c4f13ab85d920ac3b0796221457ca4894fc6578f92b022880e_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:304406009c9800285cfcc74861de6b3cc230d09438f37426e39d911a69368e34_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:304406009c9800285cfcc74861de6b3cc230d09438f37426e39d911a69368e34_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:32364fedba6ad4660e117eae90433b2ab8f6a16afb51ebfe718c356a531d71bd_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:32364fedba6ad4660e117eae90433b2ab8f6a16afb51ebfe718c356a531d71bd_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:dfccbd75027774554b10786ec939458a92c725cdf8226eda1660b6ff137d8e51_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:dfccbd75027774554b10786ec939458a92c725cdf8226eda1660b6ff137d8e51_s390x |
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:e83e6c58071dd1fbba15944e2d25ecac07dd623d58e2b31cc72a0555aa69e584_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-rhel8-operator@sha256:e83e6c58071dd1fbba15944e2d25ecac07dd623d58e2b31cc72a0555aa69e584_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:10e904f11041dd4947254df586f74f03a66d16818c4f073b8cc8d2336175f6a4_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:10e904f11041dd4947254df586f74f03a66d16818c4f073b8cc8d2336175f6a4_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:e93ec7ad08b50b54b61ccd9c69205f7b04692cb3a5c452782b92dce42f9ae4e3_s390x as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-collector-rhel8@sha256:1f03a7f23c4ffb6adb440d475075a8b11211ddd8acda772d02a904547cb5148c_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-collector-rhel8@sha256:1f03a7f23c4ffb6adb440d475075a8b11211ddd8acda772d02a904547cb5148c_amd64 |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:da206789e59d581483ffbe8e1c63519019f504c792b5ad2d5e9299d12785c675_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:da206789e59d581483ffbe8e1c63519019f504c792b5ad2d5e9299d12785c675_s390x |
| Red Hat | advanced-cluster-security/rhacs-central-db-rhel8@sha256:072eeeb7f1dd12e6f0275948d3b38b52f667e45d1304e6fd2dd28c816571d824_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-central-db-rhel8@sha256:072eeeb7f1dd12e6f0275948d3b38b52f667e45d1304e6fd2dd28c816571d824_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:3d6a461c5fe55fd478dc08f5a95c8cd813c5dc56ddbbc40c033697a1b628ca67_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:3d6a461c5fe55fd478dc08f5a95c8cd813c5dc56ddbbc40c033697a1b628ca67_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:1f624ee17785e5f2221e917459f31c81ef23421bf9374cedf9020f139e67854a_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:1f624ee17785e5f2221e917459f31c81ef23421bf9374cedf9020f139e67854a_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:317838698e27cb366ca736975f0cb0bf927533b5526caabe5a9e443d28a70487_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:317838698e27cb366ca736975f0cb0bf927533b5526caabe5a9e443d28a70487_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:3894202682fafa2a5bcc7fccd267396f6fa2c4f068f31c2cf99579a1308cde5e_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:3894202682fafa2a5bcc7fccd267396f6fa2c4f068f31c2cf99579a1308cde5e_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:54c43eb7e2952e6fe64071077a4a22965af01a2e0d4da7ee9249d3c7e31df5a4_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-rhel8@sha256:54c43eb7e2952e6fe64071077a4a22965af01a2e0d4da7ee9249d3c7e31df5a4_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:f9909a0d6d6063f36dd7dd62ed3e5ba5dab6f1f754e627e2dc0726bb124bc1f8_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:f9909a0d6d6063f36dd7dd62ed3e5ba5dab6f1f754e627e2dc0726bb124bc1f8_amd64 |
| Red Hat | advanced-cluster-security/rhacs-operator-bundle@sha256:e9cc56d2c29af677277791fdfae7796cc5f43e92772bde4adf1f168ef4aaec80_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-operator-bundle@sha256:e9cc56d2c29af677277791fdfae7796cc5f43e92772bde4adf1f168ef4aaec80_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:37f65ec7e152446ef02de2934532db772f534647e91d3909197aeaffe808693e_amd64 as a component of RHACS 4.4 for RHEL 8 | * |
…and 19 more
Timeline
- Aug 29, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:6054 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.openshift.com/acs/4.4/release_notes/44-release-notes.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2274767 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2295010 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6054.json advisory
- https://access.redhat.com/security/cve/CVE-2024-3727 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-3727 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-3727 advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://access.redhat.com/security/cve/CVE-2024-37298 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-37298 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-37298 advisory
- https://github.com/gorilla/schema/blob/main/decoder.go#L223 advisory
- https://github.com/gorilla/schema/commit/cd59f2f12cbdfa9c06aa63e425d1fe4a806967ff advisory
- https://github.com/gorilla/schema/security/advisories/GHSA-3669-72x9-r9p3 advisory