VDB
RHSA-2024%3A6708
RHSA-2024%3A6708
PUBLISHED
CVSS 8.300000190734863 HIGH
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:7f8a21b252c7cc6183e704f886d0d6f94dc01cce42afc4ca3cf05b82ab0a2bcd_s390x as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:52f1711e6c6ca2d7d9d15b4c4d52846ba98813e2d1aaf1be6ad9d9a4650287c8_s390x as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:9b026710fd2c63a42152f1573c28ef0ad1ac0a1fb5997208282776533fb90d90_ppc64le as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:9b026710fd2c63a42152f1573c28ef0ad1ac0a1fb5997208282776533fb90d90_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:d6530fce84c8d1f9ee34de95c68a2b3309e033238fdfa162b609c8aca9241eaa_amd64 as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:d6530fce84c8d1f9ee34de95c68a2b3309e033238fdfa162b609c8aca9241eaa_amd64 |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:dac6f3e8dcd7f1636aa2c37ba2f0c7d5c0712ff4de910642d8d999004ff9dba2_ppc64le as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:0af4ae93ac63e019e0e103d7287bf0b47d52f8e87c14bc04cf8f2c1536e432fa_ppc64le as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:0af4ae93ac63e019e0e103d7287bf0b47d52f8e87c14bc04cf8f2c1536e432fa_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:2c4cfb85e07d6cc7359ab459a3457ea0e682c7b78c716e50e4a180b8a8c7664a_amd64 as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:e2ee3610fe0ff075f0010b2a3928784d9998f89db72ffdc469e62092bb647cef_amd64 as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:9723e7068f959783d42ec6e9b2019eefc0c48e4d8b9b55a3a41f1e41fd656bd9_amd64 as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:10da3d4a97030f91e441968487d940b088780b7d5b00941ef870581e45766379_ppc64le as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:10da3d4a97030f91e441968487d940b088780b7d5b00941ef870581e45766379_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:8349705a4ea40ee5c6adb9f003356ade960dbb424115f8791266e596ba8edf5f_s390x as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:8349705a4ea40ee5c6adb9f003356ade960dbb424115f8791266e596ba8edf5f_s390x |
| Red Hat | advanced-cluster-security/rhacs-operator-bundle@sha256:2c62583bcb17ad8ba22b6547b155f880ce51780782f7a4b3ea8c7e8ac8c2bd33_s390x as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-operator-bundle@sha256:2c62583bcb17ad8ba22b6547b155f880ce51780782f7a4b3ea8c7e8ac8c2bd33_s390x |
| Red Hat | advanced-cluster-security/rhacs-main-rhel8@sha256:15ca3da209e504a468f849fff947f960c3917fe015d3ddac8fd3a8aba97e165b_ppc64le as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-main-rhel8@sha256:15ca3da209e504a468f849fff947f960c3917fe015d3ddac8fd3a8aba97e165b_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-central-db-rhel8@sha256:6cbd8743614c64e220dd7a843f8878728b4290fa584b2658a0e4fc8051c9de92_ppc64le as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-collector-rhel8@sha256:b9f7c336b2a632436dd30230d2e2dfc7f6a4849e17c6af727146c58dcccc6cbe_amd64 as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-collector-rhel8@sha256:b9f7c336b2a632436dd30230d2e2dfc7f6a4849e17c6af727146c58dcccc6cbe_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:6e20cc66a31f43356b13c0a4e0f191404a6a51b832266f1b570ee0335d9e0891_ppc64le as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:6e20cc66a31f43356b13c0a4e0f191404a6a51b832266f1b570ee0335d9e0891_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:65fc76b887fe1ba9be7bdf37c14e256641078d64e76811534edf8a724537a1e7_amd64 as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:65fc76b887fe1ba9be7bdf37c14e256641078d64e76811534edf8a724537a1e7_amd64 |
| Red Hat | advanced-cluster-security/rhacs-collector-rhel8@sha256:df1d4062894fb0c6d214bc2105536fa88f4993f588d56d5f2f5ee84d244a5d76_ppc64le as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-collector-rhel8@sha256:df1d4062894fb0c6d214bc2105536fa88f4993f588d56d5f2f5ee84d244a5d76_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:df1eef01f4d53c84b0998331715fbc2da0abac8c42a1de2949f253b33cbbaf09_amd64 as a component of RHACS 4.5 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:654b47b6c321a556e41038ebc6a8f5d5ef1aca1ed03e725ae7f0ed41c5fd5ff1_s390x as a component of RHACS 4.5 for RHEL 8 | advanced-cluster-security/rhacs-rhel8-operator@sha256:654b47b6c321a556e41038ebc6a8f5d5ef1aca1ed03e725ae7f0ed41c5fd5ff1_s390x |
…and 19 more
Timeline
- Sep 16, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:6708 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://docs.openshift.com/acs/4.5/release_notes/45-release-notes.html advisory
- https://access.redhat.com/security/cve/CVE-2024-3727 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2274767 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6708.json advisory
- https://www.cve.org/CVERecord?id=CVE-2024-3727 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-3727 advisory