CVE-2024-9341

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Oct 1, 2024
Updated: Dec 11, 2024
CWE ID 59

Summary

CVE-2024-9341 is a vulnerability affecting Go's containers/common library. When FIPS mode is enabled, this flaw permits container runtimes to incorrectly handle certain file paths due to insufficient validation. An attacker can utilize symbolic links to manipulate the system into mounting sensitive host directories within containers, thereby bypassing the intended container isolation and gaining unauthorized access to critical host files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Openshift Container Platform
  • Red Hat Enterprise Linux

Affected Vendors

  • Red Hat