Github.Com Containers Image vulnerabilities
2 known vulnerabilities affecting github.com/containers_image.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-3727HIGH≥ 0, < 5.30.12024-05-14
CVE-2024-3727 [HIGH] CWE-354 github.com/containers/image allows unexpected authenticated registry accesses
github.com/containers/image allows unexpected authenticated registry accesses
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
ghsaosv
CVE-2019-10214MEDIUM≥ 0, < 3.0.02022-02-15
CVE-2019-10214 [MEDIUM] CWE-522 containers/image library Insufficiently Protects Credentials
containers/image library Insufficiently Protects Credentials
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or b
ghsaosv