Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27262 | A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built. |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Wed, 06 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-08-30T15:45:03.184Z
Reserved: 2024-03-07T21:19:24.246Z
Link: CVE-2024-2307
Updated: 2024-08-01T19:11:52.858Z
Status : Awaiting Analysis
Published: 2024-03-19T17:15:12.520
Modified: 2024-11-21T09:09:28.410
Link: CVE-2024-2307
OpenCVE Enrichment
No data.
EUVD