CVE-2024-9407 is a vulnerability in the Dockerfile RUN --mount instruction's bind-propagation option, allowing improper input validation. This flaw enables attackers to mount sensitive host directories into containers during the build process, potentially modifying files and bypassing SELinux protections. With a CVSS score of 4.7 (Medium), exploitation requires high privileges and attack complexity, but can lead to high confidentiality impact. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 10 | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction
Oct 8, 2024Improper Input Validation in Buildah and Podman
Oct 1, 2024Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction
Oct 1, 2024