Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-42310.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-42310
Upstream
  • CVE-2024-2905
Published
2024-04-25T18:15:08Z
Modified
2026-04-21T04:29:29.640367Z
Summary
CVE-2024-2905 affecting package rpm-ostree for versions less than 2024.4-3
Details

A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access.

References

Affected packages

Azure Linux:3 / rpm-ostree

Package

Name
rpm-ostree
Purl
pkg:rpm/azure-linux/rpm-ostree

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2024.4-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-42310.json"