CVE Vulnerabilities

CVE-2024-3727

Improper Validation of Integrity Check Value

Published: May 14, 2024 | Modified: Oct 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

Name Vendor Start Version End Version
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-central-db-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-collector-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-collector-slim-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-main-rhel8:4.4.5-4 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-operator-bundle:4.4.5-3 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-rhel8-operator:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-db-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.4.5-3 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:4.4.5-2 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.4.5-3 *
Red Hat Advanced Cluster Security 4.4 RedHat advanced-cluster-security/rhacs-scanner-v4-rhel8:4.4.5-3 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-central-db-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-collector-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-collector-slim-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-main-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-operator-bundle:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-rhel8-operator:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-db-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:4.5.2-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.5.2-2 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-v4-rhel8:4.5.2-2 *
Red Hat Enterprise Linux 8 RedHat container-tools:rhel8-8100020240808093819.afee755d *
Red Hat Migration Toolkit for Containers 1.8 RedHat rhmtc/openshift-migration-controller-rhel8:v1.8.4-22 *
Red Hat OpenShift Container Platform 4.13 RedHat podman-3:4.4.1-14.rhaos4.13.el9 *
Red Hat OpenShift Container Platform 4.13 RedHat skopeo-2:1.11.3-3.rhaos4.13.el9 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-operator-lifecycle-manager:v4.14.0-202407260439.p0.g8d9b39e.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat podman-3:4.4.1-19.rhaos4.14.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat skopeo-2:1.11.3-3.rhaos4.14.el9 *
Red Hat OpenShift Container Platform 4.15 RedHat podman-3:4.4.1-30.rhaos4.15.el9 *
Red Hat OpenShift Container Platform 4.15 RedHat skopeo-2:1.11.3-4.rhaos4.15.el8 *
Red Hat OpenShift Container Platform 4.15 RedHat openshift4/ose-operator-lifecycle-manager-rhel9:v4.15.0-202407230407.p0.gf3f8de5.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat podman-4:4.9.4-5.1.rhaos4.16.el8 *
Red Hat OpenShift Container Platform 4.16 RedHat skopeo-2:1.14.4-1.rhaos4.16.el8 *
Red Hat OpenShift Container Platform 4.16 RedHat cri-o-0:1.29.5-7.rhaos4.16.git7db4ada.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-operator-lifecycle-manager-rhel9:v4.16.0-202407171536.p0.g1551101.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-machine-config-rhel9-operator:v4.16.0-202409162206.p0.g6a425ab.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-agent-installer-orchestrator-rhel9:v4.16.0-202409231504.p0.g342902b.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-machine-config-rhel9-operator:v4.17.0-202409122005.p0.gb170ad0.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-olm-operator-controller-rhel9:v4.17.0-202409100034.p0.g8d16b39.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-operator-lifecycle-manager-rhel9:v4.17.0-202409101338.p0.gb0d86a0.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-operator-registry-rhel9:v4.17.0-202409101338.p0.gb0d86a0.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-agent-installer-orchestrator-rhel9:v4.17.0-202410022234.p0.gfbc55c6.assembly.stream.el9 *
RHEL-9-CNV-4.15 RedHat container-native-virtualization/virt-cdi-controller-rhel9:v4.15.5-7 *
Golang-github-opencontainers-go-digest Ubuntu mantic *

Potential Mitigations

References