flatcar/Flatcar

update: containers-image

Closed this issue · 0 comments

Name: containers-image
CVEs: CVE-2024-3727
CVSSs: 8.3
Action Needed: update to >= 5.30.1

Summary: A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

See also https://bugzilla.redhat.com/show_bug.cgi?id=2274767.

refmap.gentoo: TBD