CVE-2024-49838

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 125
CWE ID 126

Summary

CVE-2024-49838 is a newly disclosed vulnerability that affects the Open Container Initiative Image Exchange format (OCI IE). The issue arises when the OCI IE encounters an image manifest with an invalid length during parsing. This leads to an information disclosure, where sensitive data such as image metadata and configuration details may be revealed. Attackers could potentially exploit this vulnerability to gain unauthorized access to sensitive information, making it a significant security concern for organizations using the OCI IE. It is recommended that affected systems be updated as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share