CVE-2024-3727
Containers/image: digest type does not guarantee valid type
CVSS Score
8.3
EPSS Score
0.6%
EPSS Percentile
68th
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
| CWE | CWE-354 |
| Published | May 9, 2024 |
| Last Updated | Apr 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new high vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Red Hat / OADP-1.3-RHEL-9
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.4
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Advanced Cluster Security 4.5
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Migration Toolkit for Containers 1.8
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.13
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.13
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.14
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.15
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.16
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.17
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected Red Hat / Red Hat OpenShift Container Platform 4.18
All versions affected Red Hat / RHEL-9-CNV-4.15
All versions affected Red Hat / Multicluster Engine for Kubernetes
All versions affected Red Hat / Multicluster Engine for Kubernetes
All versions affected Red Hat / Multicluster Engine for Kubernetes
All versions affected Red Hat / Multicluster Engine for Kubernetes
All versions affected Red Hat / Multicluster Engine for Kubernetes
All versions affected Red Hat / OpenShift Developer Tools and Services
All versions affected Red Hat / OpenShift Developer Tools and Services
All versions affected Red Hat / OpenShift Serverless
All versions affected Red Hat / OpenShift Serverless
All versions affected Red Hat / OpenShift Source-to-Image (S2I)
All versions affected Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Advanced Cluster Security 3
All versions affected Red Hat / Red Hat Ansible Automation Platform 1.2
All versions affected Red Hat / Red Hat Ansible Automation Platform 2
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat OpenShift Container Platform 3.11
All versions affected Red Hat / Red Hat OpenShift Container Platform 3.11
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform Assisted Installer 1
All versions affected Red Hat / Red Hat OpenShift Container Platform Assisted Installer 1
All versions affected Red Hat / Red Hat OpenShift Container Platform Assisted Installer 1
All versions affected Red Hat / Red Hat OpenShift Dev Spaces
All versions affected Red Hat / Red Hat Openshift Sandboxed Containers
All versions affected Red Hat / Red Hat Openshift Sandboxed Containers
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenShift Virtualization 4
All versions affected Red Hat / Red Hat OpenStack Platform 16.2
All versions affected Red Hat / Red Hat Quay 3
All versions affected References
access.redhat.com: https://access.redhat.com/errata/RHSA-2024:0045 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:3718 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4159 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4613 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4850 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:4960 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:5258 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:5951 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6054 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6122 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6708 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6818 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:6824 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7164 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7174 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7182 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7187 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7922 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7941 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8260 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8425 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9097 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9098 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9102 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9960 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-3727 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2274767 lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/4HEYS34N55G7NOQZKNEXZKQVNDGEICCD/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/6B37TXOKTKDBE2V26X2NSP7JKNMZOFVP/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/CYT3D2P3OJKISNFKOOHGY6HCUCQZYAVR/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/DLND3YDQQRWVRIUPL2G5UKXP5L3VSBBT/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/DTOMYERG5ND4QFDHC4ZSGCED3T3ESRSC/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/FBZQ2ZRMFEUQ35235B2HWPSXGDCBZHFV/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/GD2GSBQTBLYADASUBHHZV2CZPTSLIPQJ/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/QFXMF3VVKIZN7ZMB7PKZCSWV6MOMTGMQ/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/[email protected]/message/SFVSMR7TNLO2KPWJSW4CF64C2QMQXCIN/