VDB
RHSA-2024:6054
RHSA-2024:6054
PUBLISHED
CVSS 8.300000190734863 HIGH
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:0b590586a0bfc3d6399505dfb5ca1367c232d0b13245fd3ab9b0e5ac24a0b5a2_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-rhel8-operator@sha256:0b590586a0bfc3d6399505dfb5ca1367c232d0b13245fd3ab9b0e5ac24a0b5a2_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:6f78b7cbdee3e6c08c6ebcdf67dc2c49dd93bba1fa0bcbc42154bbd6bd6b60f3_ppc64le as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:e0617ff16dc01afccf934a956c4dd3c7fab847d92e520b0d9358bd7bc3fa1582_ppc64le as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-main-rhel8@sha256:9a11dad9b17cc9c4f13ab85d920ac3b0796221457ca4894fc6578f92b022880e_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-main-rhel8@sha256:9a11dad9b17cc9c4f13ab85d920ac3b0796221457ca4894fc6578f92b022880e_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:304406009c9800285cfcc74861de6b3cc230d09438f37426e39d911a69368e34_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:304406009c9800285cfcc74861de6b3cc230d09438f37426e39d911a69368e34_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:e93ec7ad08b50b54b61ccd9c69205f7b04692cb3a5c452782b92dce42f9ae4e3_s390x as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-collector-rhel8@sha256:1f03a7f23c4ffb6adb440d475075a8b11211ddd8acda772d02a904547cb5148c_amd64 as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:32364fedba6ad4660e117eae90433b2ab8f6a16afb51ebfe718c356a531d71bd_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:32364fedba6ad4660e117eae90433b2ab8f6a16afb51ebfe718c356a531d71bd_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:dfccbd75027774554b10786ec939458a92c725cdf8226eda1660b6ff137d8e51_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:dfccbd75027774554b10786ec939458a92c725cdf8226eda1660b6ff137d8e51_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:d09e9eeec5cdcbc7db49814caf033868cbc91273459debfcac94f58151573762_amd64 as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:0b590586a0bfc3d6399505dfb5ca1367c232d0b13245fd3ab9b0e5ac24a0b5a2_s390x as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:e83e6c58071dd1fbba15944e2d25ecac07dd623d58e2b31cc72a0555aa69e584_ppc64le as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-rhel8-operator@sha256:e83e6c58071dd1fbba15944e2d25ecac07dd623d58e2b31cc72a0555aa69e584_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:10e904f11041dd4947254df586f74f03a66d16818c4f073b8cc8d2336175f6a4_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:10e904f11041dd4947254df586f74f03a66d16818c4f073b8cc8d2336175f6a4_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:16deab5ea78fbe3d6f4684ef8b4d071dd2408ba46da9f6fc79a9c0af1da16165_ppc64le as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:e93ec7ad08b50b54b61ccd9c69205f7b04692cb3a5c452782b92dce42f9ae4e3_s390x as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-collector-rhel8@sha256:1f03a7f23c4ffb6adb440d475075a8b11211ddd8acda772d02a904547cb5148c_amd64 as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-collector-rhel8@sha256:1f03a7f23c4ffb6adb440d475075a8b11211ddd8acda772d02a904547cb5148c_amd64 |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:a13aab1f8c4294f490284b5f0c73fc77b1ee08b65a3d1cae23aacb5db1687926_s390x as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:da206789e59d581483ffbe8e1c63519019f504c792b5ad2d5e9299d12785c675_s390x as a component of RHACS 4.4 for RHEL 8 | advanced-cluster-security/rhacs-roxctl-rhel8@sha256:da206789e59d581483ffbe8e1c63519019f504c792b5ad2d5e9299d12785c675_s390x |
| Red Hat | advanced-cluster-security/rhacs-main-rhel8@sha256:3877057e49d5da93372d239055b6506b23ef430da60d0eca371c4c5a619b1ae6_amd64 as a component of RHACS 4.4 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:dfccbd75027774554b10786ec939458a92c725cdf8226eda1660b6ff137d8e51_s390x as a component of RHACS 4.4 for RHEL 8 | * |
…and 59 more
Timeline
- Aug 29, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.openshift.com/acs/4.4/release_notes/44-release-notes.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2295010 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6054.json advisory
- https://access.redhat.com/security/cve/CVE-2024-3727 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-3727 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-37298 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-37298 advisory
- https://github.com/gorilla/schema/blob/main/decoder.go#L223 advisory
- https://github.com/gorilla/schema/security/advisories/GHSA-3669-72x9-r9p3 advisory
- https://access.redhat.com/errata/RHSA-2024:6054 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2274767 issue
- https://nvd.nist.gov/vuln/detail/CVE-2024-3727 advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://access.redhat.com/security/cve/CVE-2024-37298 advisory
- https://github.com/gorilla/schema/commit/cd59f2f12cbdfa9c06aa63e425d1fe4a806967ff advisory