CVE-2024-0567
CVE Details
Visit the official vulnerability details page for CVE-2024-0567 to learn more.
Initial Publication
11/13/2024
Last Update
12/12/2024
Third Party Dependency
libgnutls30
NIST CVE Summary
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
CVE Severity
Our Official Summary
This vulnerability in GnuTLS, allows an unauthenticated, remote client or attacker to initiate a denial of service attack. The images where this vulnerability is have controls in place are not accessible outside the cluster. So the attacker needs to gain privileged access to the cluster to attempt this exploit. Also the containers do not allow execution of arbitrary code. Impact of this exploit is also low, since container reduces the attack surface.
Status
Ongoing
Affected Products & Versions
Version | Palette Enterprise | Palette Enterprise Airgap | VerteX | VerteX Airgap |
---|---|---|---|---|
4.4.20 | ⚠️ Impacted | ✅ No Impact | ⚠️ Impacted | ✅ No Impact |
Revision History
Date | Revision |
---|---|
12/12/2024 | Official summary revised: This vulnerability in GnuTLS, allows an unauthenticated, remote client or attacker to initiate a denial of service attack. The images where this vulnerability is have controls in place are not accessible outside the cluster. So the attacker needs to gain privileged access to the cluster to attempt this exploit. Also the containers do not allow execution of arbitrary code. Impact of this exploit is also low, since container reduces the attack surface. |
12/12/2024 | Official summary added |