CVE-2024-9341
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Oct 1, 2024
Updated: Dec 11, 2024
CWE ID 59
Summary
CVE-2024-9341 is a vulnerability affecting Go's containers/common library. When FIPS mode is enabled, this flaw permits container runtimes to incorrectly handle certain file paths due to insufficient validation. An attacker can utilize symbolic links to manipulate the system into mounting sensitive host directories within containers, thereby bypassing the intended container isolation and gaining unauthorized access to critical host files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Openshift Container Platform
- Red Hat Enterprise Linux
Affected Vendors
- Red Hat