PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/49f58034.3956752c.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:41:27 UTC 5,015 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["12561"],{425509:function(e,i,t){t.r(i),t.d(i,{frontMatter:()=>l,toc:()=>o,default:()=>u,metadata:()=>n,assets:()=>a,contentTitle:()=>c});var n=JSON.parse('{"id":"security-bulletins/reports/pc-cve-2024-9341","title":"CVE-2024-9341","description":"Lifecycle of CVE-2024-9341","source":"@site/docs/docs-content/security-bulletins/reports/pc-cve-2024-9341.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/pc-cve-2024-9341","permalink":"/security-bulletins/reports/pc-cve-2024-9341","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/pc-cve-2024-9341.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2024-9341","title":"CVE-2024-9341","description":"Lifecycle of CVE-2024-9341","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2024-9287","permalink":"/security-bulletins/reports/pc-cve-2024-9287"},"next":{"title":"CVE-2025-1097","permalink":"/security-bulletins/reports/pc-cve-2025-1097"}}'),s=t(474848),r=t(884429);let l={sidebar_label:"CVE-2024-9341",title:"CVE-2024-9341",description:"Lifecycle of CVE-2024-9341",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},c,a={},o=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function d(e){let i={a:"a",h2:"h2",p:"p",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(i.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,s.jsxs)(i.p,{children:["Visit the official vulnerability details page for ",(0,s.jsx)(i.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2024-9341",children:"CVE-2024-9341"})," to learn more."]}),"\n",(0,s.jsx)(i.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,s.jsx)(i.p,{children:"10/10/2025"}),"\n",(0,s.jsx)(i.h2,{id:"last-update",children:"Last Update"}),"\n",(0,s.jsx)(i.p,{children:"10/14/2025"}),"\n",(0,s.jsx)(i.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,s.jsx)(i.p,{children:"github.com/containers/common"}),"\n",(0,s.jsx)(i.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,s.jsx)(i.p,{children:"A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system."}),"\n",(0,s.jsx)(i.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,s.jsx)(i.p,{children:(0,s.jsx)(i.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2024-9341",children:"8.2"})}),"\n",(0,s.jsx)(i.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,s.jsx)(i.p,{children:"This vulnerability is a false positive. Although this is reported by the scanning tools on some of the components, further checks indicate the symbol/function with the vulnerability while present is not being used."}),"\n",(0,s.jsx)(i.h2,{id:"status",children:"Status"}),"\n",(0,s.jsx)(i.p,{children:"Open"}),"\n",(0,s.jsx)(i.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,s.jsx)(i.p,{children:"This CVE is non-impacting as the impacting symbol and/or function is not used in the product"}),"\n",(0,s.jsx)(i.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,s.jsx)(i.p,{children:"No revisions available."})]})}function u(e={}){let{wrapper:i}={...(0,r.R)(),...e.components};return i?(0,s.jsx)(i,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},884429:function(e,i,t){t.d(i,{R:()=>l,x:()=>c});var n=t(296540);let s={},r=n.createContext(s);function l(e){let i=n.useContext(r);return n.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function c(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:l(e.components),n.createElement(r.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.