๐Ÿ” CVE Alert

CVE-2024-3727

HIGH 8.3

Containers/image: digest type does not guarantee valid type

CVSS Score
8.3
EPSS Score
0.6%
EPSS Percentile
68th

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

CWE CWE-354
Published May 9, 2024
Last Updated Apr 18, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new high vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Red Hat / OADP-1.3-RHEL-9
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Migration Toolkit for Containers 1.8
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.13
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.13
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected
Red Hat / RHEL-9-CNV-4.15
All versions affected
Red Hat / Multicluster Engine for Kubernetes
All versions affected
Red Hat / Multicluster Engine for Kubernetes
All versions affected
Red Hat / Multicluster Engine for Kubernetes
All versions affected
Red Hat / Multicluster Engine for Kubernetes
All versions affected
Red Hat / Multicluster Engine for Kubernetes
All versions affected
Red Hat / OpenShift Developer Tools and Services
All versions affected
Red Hat / OpenShift Developer Tools and Services
All versions affected
Red Hat / OpenShift Serverless
All versions affected
Red Hat / OpenShift Serverless
All versions affected
Red Hat / OpenShift Source-to-Image (S2I)
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Advanced Cluster Security 3
All versions affected
Red Hat / Red Hat Ansible Automation Platform 1.2
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat OpenShift Container Platform 3.11
All versions affected
Red Hat / Red Hat OpenShift Container Platform 3.11
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform Assisted Installer 1
All versions affected
Red Hat / Red Hat OpenShift Container Platform Assisted Installer 1
All versions affected
Red Hat / Red Hat OpenShift Container Platform Assisted Installer 1
All versions affected
Red Hat / Red Hat OpenShift Dev Spaces
All versions affected
Red Hat / Red Hat Openshift Sandboxed Containers
All versions affected
Red Hat / Red Hat Openshift Sandboxed Containers
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenStack Platform 16.2
All versions affected
Red Hat / Red Hat Quay 3
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2024:0045 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:3718 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4159 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4613 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4850 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4960 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:5258 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:5951 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6054 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6122 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6708 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6818 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6824 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7164 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7174 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7182 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7187 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7922 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7941 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8260 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8425 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9097 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9098 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9102 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9960 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-3727 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2274767 lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/4HEYS34N55G7NOQZKNEXZKQVNDGEICCD/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/6B37TXOKTKDBE2V26X2NSP7JKNMZOFVP/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/CYT3D2P3OJKISNFKOOHGY6HCUCQZYAVR/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/DLND3YDQQRWVRIUPL2G5UKXP5L3VSBBT/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/DTOMYERG5ND4QFDHC4ZSGCED3T3ESRSC/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/FBZQ2ZRMFEUQ35235B2HWPSXGDCBZHFV/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/GD2GSBQTBLYADASUBHHZV2CZPTSLIPQJ/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/QFXMF3VVKIZN7ZMB7PKZCSWV6MOMTGMQ/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN/