CVE-2024-9341
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.7
Source: NVD
Description
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.
Affected (9)
Products: Containers: Common · Redhat: Enterprise Linux, Openshift Container Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 4.12 |
References (17)
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Product
Source: secalert@redhat.com
Product
Timeline
No history available yet.