Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9341


A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.


Published

2024-10-01T19:15:09.500

Last Modified

2024-12-11T04:15:06.090

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-59

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application containers common * Yes
Application redhat openshift_container_platform 4.12 Yes
Application redhat openshift_container_platform 4.13 Yes
Application redhat openshift_container_platform 4.14 Yes
Application redhat openshift_container_platform 4.15 Yes
Application redhat openshift_container_platform 4.16 Yes
Application redhat openshift_container_platform 4.17 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux 9.0 Yes

References