CVE-2024-3727
published 2024-05-14CVE-2024-3727: A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a…
PriorityP343high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
1.28%
67.0th percentile
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-containers-image | < golang-github-containers-image 5.29.3-1 (forky) | golang-github-containers-image 5.29.3-1 (forky) |
| github.com | containers_image | >= 0 < 5.30.1 | 5.30.1 |
| github.com | containers_image_v5 | >= 0 < 5.29.3 | 5.29.3 |
| github.com | containers_image_v5 | >= 5.30.0 < 5.30.1 | 5.30.1 |
| msrc | azl3_containerized-data-importer_1.57.0-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_containerized-data-importer_1.57.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_ig_0.25.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_ig_0.29.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_libcontainers-common_20240213-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_libcontainers-common_20240213-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_skopeo_1.14.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_skopeo_1.14.4-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_containerized-data-importer_1.55.0-19_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_containerized-data-importer_1.55.0-23_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cri-o_1.22.3-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libcontainers-common_20210626-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_skopeo_1.14.2-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_skopeo_1.14.2-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.3HIGH
vendor_debian8.3HIGH
vendor_msrc8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Containers/image: digest type does not guarantee valid type
vendor_msrc·2024-05-14·CVSS 8.3
CVE-2024-3727 [HIGH] CWE-354 Containers/image: digest type does not guarantee valid type
Containers/image: digest type does not guarantee valid type
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:/
Red Hat
containers/image: digest type does not guarantee valid type
vendor_redhat·2024-05-09·CVSS 8.3
CVE-2024-3727 [HIGH] CWE-354 containers/image: digest type does not guarantee valid type
containers/image: digest type does not guarantee valid type
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Statement: Some conditions are necessary for this attack to occur, such as the attacker being able to upload malicious images to the registry and persuade a victim to pull them. Hence, the severity of this flaw was rated as Moderate.
Package: multicluster-
Debian
CVE-2024-3727: golang-github-containers-image - A flaw was found in the github.com/containers/image library. This flaw allows at...
vendor_debian·2024·CVSS 8.3
CVE-2024-3727 [HIGH] CVE-2024-3727: golang-github-containers-image - A flaw was found in the github.com/containers/image library. This flaw allows at...
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.29.3-1)
sid: resolved (fixed in 5.29.3-1)
trixie: resolved (fixed in 5.29.3-1)
OSV
Unexpected authenticated registry accesses in github.com/containers/image/v5
osv·2024-05-20
CVE-2024-3727 Unexpected authenticated registry accesses in github.com/containers/image/v5
Unexpected authenticated registry accesses in github.com/containers/image/v5
An attacker may trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
OSV
github.com/containers/image allows unexpected authenticated registry accesses
osv·2024-05-14
CVE-2024-3727 [HIGH] github.com/containers/image allows unexpected authenticated registry accesses
github.com/containers/image allows unexpected authenticated registry accesses
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
GHSA
github.com/containers/image allows unexpected authenticated registry accesses
ghsa·2024-05-14
CVE-2024-3727 [HIGH] CWE-354 github.com/containers/image allows unexpected authenticated registry accesses
github.com/containers/image allows unexpected authenticated registry accesses
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
OSV
CVE-2024-3727: A flaw was found in the github
osv·2024-05-14·CVSS 8.3
CVE-2024-3727 [HIGH] CVE-2024-3727: A flaw was found in the github
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:0045https://access.redhat.com/errata/RHSA-2024:3718https://access.redhat.com/errata/RHSA-2024:4159https://access.redhat.com/errata/RHSA-2024:4613https://access.redhat.com/errata/RHSA-2024:4850https://access.redhat.com/errata/RHSA-2024:4960https://access.redhat.com/errata/RHSA-2024:5258https://access.redhat.com/errata/RHSA-2024:5951https://access.redhat.com/errata/RHSA-2024:6054https://access.redhat.com/errata/RHSA-2024:6122https://access.redhat.com/errata/RHSA-2024:6708https://access.redhat.com/errata/RHSA-2024:6818https://access.redhat.com/errata/RHSA-2024:6824https://access.redhat.com/errata/RHSA-2024:7164https://access.redhat.com/errata/RHSA-2024:7174https://access.redhat.com/errata/RHSA-2024:7182https://access.redhat.com/errata/RHSA-2024:7187https://access.redhat.com/errata/RHSA-2024:7922https://access.redhat.com/errata/RHSA-2024:7941https://access.redhat.com/errata/RHSA-2024:8260https://access.redhat.com/errata/RHSA-2024:8425https://access.redhat.com/errata/RHSA-2024:9097https://access.redhat.com/errata/RHSA-2024:9098https://access.redhat.com/errata/RHSA-2024:9102https://access.redhat.com/errata/RHSA-2024:9960https://access.redhat.com/security/cve/CVE-2024-3727https://bugzilla.redhat.com/show_bug.cgi?id=2274767https://access.redhat.com/errata/RHSA-2024:0045https://access.redhat.com/errata/RHSA-2024:4159https://access.redhat.com/errata/RHSA-2024:4613https://access.redhat.com/security/cve/CVE-2024-3727https://bugzilla.redhat.com/show_bug.cgi?id=2274767https://lists.fedoraproject.org/archives/list/[email protected]/message/4HEYS34N55G7NOQZKNEXZKQVNDGEICCD/https://lists.fedoraproject.org/archives/list/[email protected]/message/6B37TXOKTKDBE2V26X2NSP7JKNMZOFVP/https://lists.fedoraproject.org/archives/list/[email protected]/message/CYT3D2P3OJKISNFKOOHGY6HCUCQZYAVR/https://lists.fedoraproject.org/archives/list/[email protected]/message/DLND3YDQQRWVRIUPL2G5UKXP5L3VSBBT/https://lists.fedoraproject.org/archives/list/[email protected]/message/DTOMYERG5ND4QFDHC4ZSGCED3T3ESRSC/https://lists.fedoraproject.org/archives/list/[email protected]/message/FBZQ2ZRMFEUQ35235B2HWPSXGDCBZHFV/https://lists.fedoraproject.org/archives/list/[email protected]/message/GD2GSBQTBLYADASUBHHZV2CZPTSLIPQJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/QFXMF3VVKIZN7ZMB7PKZCSWV6MOMTGMQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN/
2024-05-14
Published