Executive Summary

Informations
Name CVE-2024-9341 First vendor Publication 2024-10-01
Vendor Cve Last vendor Modification 2024-12-11

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Overall CVSS Score 8.2
Base Score 8.2 Environmental Score 8.2
impact SubScore 4.7 Temporal Score 8.2
Exploitabality Sub Score 2.8
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction Required
Scope Changed Confidentiality Impact High
Integrity Impact Low Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9341

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Application 6
Os 2

Sources (Detail)

https://access.redhat.com/errata/RHSA-2024:10147
https://access.redhat.com/errata/RHSA-2024:10818
https://access.redhat.com/errata/RHSA-2024:7925
https://access.redhat.com/errata/RHSA-2024:8039
https://access.redhat.com/errata/RHSA-2024:8112
https://access.redhat.com/errata/RHSA-2024:8238
https://access.redhat.com/errata/RHSA-2024:8263
https://access.redhat.com/errata/RHSA-2024:8428
https://access.redhat.com/errata/RHSA-2024:8690
https://access.redhat.com/errata/RHSA-2024:8694
https://access.redhat.com/errata/RHSA-2024:8846
https://access.redhat.com/errata/RHSA-2024:9454
https://access.redhat.com/errata/RHSA-2024:9459
https://access.redhat.com/security/cve/CVE-2024-9341
https://bugzilla.redhat.com/show_bug.cgi?id=2315691
https://github.com/containers/common/blob/384f77532f67afc8a73d8e0c4adb0d195df...
https://github.com/containers/common/blob/384f77532f67afc8a73d8e0c4adb0d195df...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2024-12-11 09:20:32
  • Multiple Updates
2024-11-27 00:23:08
  • Multiple Updates
2024-11-25 09:23:09
  • Multiple Updates
2024-11-23 00:23:06
  • Multiple Updates
2024-11-12 21:17:24
  • Multiple Updates
2024-11-07 13:27:52
  • Multiple Updates
2024-11-07 00:27:48
  • Multiple Updates
2024-11-05 13:27:50
  • Multiple Updates
2024-10-31 13:28:03
  • Multiple Updates
2024-10-24 21:28:31
  • Multiple Updates
2024-10-24 05:28:08
  • Multiple Updates
2024-10-16 09:27:34
  • Multiple Updates
2024-10-16 00:27:38
  • Multiple Updates
2024-10-14 21:27:32
  • Multiple Updates
2024-10-04 17:27:26
  • Multiple Updates
2024-10-02 00:27:31
  • First insertion