Skip to main content
Version: latest

CVE-2024-0567

CVE Details

Visit the official vulnerability details page for CVE-2024-0567 to learn more.

Initial Publication

11/13/2024

Last Update

12/12/2024

Third Party Dependency

libgnutls30

NIST CVE Summary

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

CVE Severity

7.5

Our Official Summary

This vulnerability in GnuTLS, allows an unauthenticated, remote client or attacker to initiate a denial of service attack. The images where this vulnerability is have controls in place are not accessible outside the cluster. So the attacker needs to gain privileged access to the cluster to attempt this exploit. Also the containers do not allow execution of arbitrary code. Impact of this exploit is also low, since container reduces the attack surface.

Status

Ongoing

Affected Products & Versions

VersionPalette EnterprisePalette Enterprise AirgapVerteXVerteX Airgap
4.4.20⚠️ Impacted✅ No Impact⚠️ Impacted✅ No Impact

Revision History

DateRevision
12/12/2024Official summary revised: This vulnerability in GnuTLS, allows an unauthenticated, remote client or attacker to initiate a denial of service attack. The images where this vulnerability is have controls in place are not accessible outside the cluster. So the attacker needs to gain privileged access to the cluster to attempt this exploit. Also the containers do not allow execution of arbitrary code. Impact of this exploit is also low, since container reduces the attack surface.
12/12/2024Official summary added