CVE-2024-9341 is a high-severity vulnerability in the Go containers/common library, affecting various container runtimes and Red Hat products, including OpenShift Container Platform. When FIPS mode is enabled, improper validation of file paths allows attackers to exploit symbolic links, enabling them to mount sensitive host directories inside containers and access critical host files, thereby bypassing isolation. The attack requires user interaction (UI:R) but can be executed remotely (AV:N) with low complexity (AC:L), leading to high confidentiality impact (C:H) and low integrity impact (I:L). Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:containers:common:*:*:*:*:*:go:*:* | ||
4.12CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* | ||
4.13CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:* | ||
4.14CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:* | ||
4.15CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library
Oct 8, 2024Link Following in github.com/containers/common
Oct 1, 2024Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library
Oct 1, 2024