Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-62476

CVE-2024-41110 in the catalog container base image of managed bundles

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • 4.17.0
    • Containers
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

          Critical CVE in the base image for the Addon catalog:
      Fixable CVE-2024-41110 (CVSS 9.9) (severity Critical) found in component 'github.com/docker/docker' (version v24.0.7+incompatible) in container 'registry-server', resolved by version 25.0.6
      
      
      Example image catalog: quay.io/osd-addons/acs-fleetshard-index@sha256:e271ff1c9434ef32d291cdbb7f2fbf0ecabc67784491ed0dd98703d32486a450

      Version-Release number of selected component (if applicable):

          

      How reproducible:

          Use managed bundles https://gitlab.cee.redhat.com/service/managed-tenants-bundles

      Steps to Reproduce:

          1. Use managed bundles (Addon flow) on the cluster
          2. It will install the catalog for the addon 
          3. The catalog container will have CVE
          

      Actual results:

          The managed bundles deploys a container with CVE

      Expected results:

          No CVE from managed bundles infra containers  

      Additional info:

       

              tsweeney@redhat.com Tom Sweeney
              rh-ee-akurlov Aleksandr Kurlov
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: