Insufficient verification of data authenticity in moby - CVE-2024-24557

 

Insufficient verification of data authenticity in moby - CVE-2024-24557

Published: February 2, 2024


Vulnerability identifier: #VU86049
CSH Severity: Medium
CVSS v4 BT: 2.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-24557
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient verification of data authenticity. A remote attacker can poison victim´s cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps.


Affected software

moby
Gentoo Linux
Amazon Linux AMI
openEuler
Guardium Data Security Center (GDSC)
Storage Ceph
IBM Cloud Pak for Watson AIOps
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Intel In-Band Manageability
IBM Edge Application Manager
Splunk Enterprise
IBM Concert Software
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM Cloud Pak System
IBM DB2
Red Hat Ceph Storage
docker-engine
docker
app-containers/docker

How to mitigate CVE-2024-24557

Install updates from vendor's website.

moby - addressed in versions 24.0.9, 25.0.2
Guardium Data Security Center (GDSC) - update to 3.7.2
Intel In-Band Manageability - update to 4.2.2
IBM Edge Application Manager - update to 4.5.6
Storage Ceph - update to 8.1z1
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
IBM Concert Software - update to 1.0.1
IBM Cloud Pak System - update to 2.3.4.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
IBM DB2 - update to 5.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3, 9.1.0
docker-engine - update to 18.09.0-263
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
docker - update to 25.0.3-1
app-containers/docker - update to 25.0.4
IBM Observability with Instana - update to 271

External References

Related Security Bulletins