CyberzSOC

Applicability
← Back to CVE-2024-23651

CVE-2024-23651

moby

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2026-08-04
2 affected 31 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-10
3 affected 3 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-05-29
1 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (38)

Product Status Versions Remediation Source
red_hat_openshift_dev_spaces:devspaces/traefik-rhel8 devspaces/traefik-rhel8 as a component of Red Hat OpenShift Dev Spaces affected devspaces/traefik-rhel8 workaround csaf_redhat
red_hat_quay_3:quay/quay-builder-rhel8 quay/quay-builder-rhel8 as a component of Red Hat Quay 3 affected quay/quay-builder-rhel8 workaround csaf_redhat
red_hat_enterprise_linux_8:buildah::container-tools:rhel8 buildah (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present buildah::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:buildah buildah as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: buildah not applicable csaf_redhat
red_hat_enterprise_linux_8:buildah-tests::container-tools:rhel8 buildah-tests (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present buildah-tests::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:buildah-tests buildah-tests as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: buildah-tests not applicable csaf_redhat
red_hat_enterprise_linux_8:buildah.src::container-tools:rhel8 buildah.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present buildah.src::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:buildah.src buildah.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: buildah.src not applicable csaf_redhat
openshift_developer_tools_and_services:odo.src odo.src as a component of OpenShift Developer Tools and Services not affected vulnerable code not present no version stated vendor label: odo.src not applicable csaf_redhat
red_hat_openshift_container_platform_4:openshift-clients openshift-clients as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present no version stated vendor label: openshift-clients not applicable csaf_redhat
red_hat_openshift_container_platform_4:openshift-clients-redistributable openshift-clients-redistributable as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present no version stated vendor label: openshift-clients-redistributable not applicable csaf_redhat
red_hat_ansible_automation_platform_1.2:openshift-clients.src openshift-clients.src as a component of Red Hat Ansible Automation Platform 1.2 not affected vulnerable code not present no version stated vendor label: openshift-clients.src not applicable csaf_redhat
red_hat_openshift_container_platform_4:openshift-clients.src openshift-clients.src as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present no version stated vendor label: openshift-clients.src not applicable csaf_redhat
openshift_serverless:openshift-serverless-1/client-kn-rhel8 openshift-serverless-1/client-kn-rhel8 as a component of OpenShift Serverless not affected vulnerable code not present openshift-serverless-1/client-kn-rhel8 not applicable csaf_redhat
openshift_serverless:openshift-serverless-clients.src openshift-serverless-clients.src as a component of OpenShift Serverless not affected vulnerable code not present no version stated vendor label: openshift-serverless-clients.src not applicable csaf_redhat
openshift_service_mesh_2:openshift-service-mesh/istio-cni-rhel8 openshift-service-mesh/istio-cni-rhel8 as a component of OpenShift Service Mesh 2 not affected vulnerable code not present openshift-service-mesh/istio-cni-rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_8:podman::container-tools:rhel8 podman (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman podman as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-catatonit::container-tools:rhel8 podman-catatonit (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-catatonit::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman-catatonit podman-catatonit as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman-catatonit not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-docker::container-tools:rhel8 podman-docker (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-docker::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman-docker podman-docker as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman-docker not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-gvproxy::container-tools:rhel8 podman-gvproxy (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-gvproxy::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman-gvproxy podman-gvproxy as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman-gvproxy not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-manpages::container-tools:rhel8 podman-manpages (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-manpages::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-plugins::container-tools:rhel8 podman-plugins (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-plugins::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman-plugins podman-plugins as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman-plugins not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-remote::container-tools:rhel8 podman-remote (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-remote::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman-remote podman-remote as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman-remote not applicable csaf_redhat
red_hat_enterprise_linux_8:podman-tests::container-tools:rhel8 podman-tests (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman-tests::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman-tests podman-tests as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman-tests not applicable csaf_redhat
red_hat_enterprise_linux_8:podman.src::container-tools:rhel8 podman.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present podman.src::container-tools:rhel8 not applicable csaf_redhat
red_hat_enterprise_linux_9:podman.src podman.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: podman.src not applicable csaf_redhat
github.com/moby/buildkit affected < 0.12.5 vendor fix → 0.12.5 osv GHSA-m3r6-h7wv-7xxv
https://github.com/moby/buildkit affected < bac3f2b673f3f9d33e79046008e7a38e856b3dc6 vendor fix → bac3f2b673f3f9d33e79046008e7a38e856b3dc6 osv
github.com/moby/buildkit fixed 0.12.5 vendor fix → 0.12.5 osv GHSA-m3r6-h7wv-7xxv
https://github.com/moby/buildkit fixed bac3f2b673f3f9d33e79046008e7a38e856b3dc6 vendor fix → bac3f2b673f3f9d33e79046008e7a38e856b3dc6 osv
moby/buildkit moby · buildkit affected < 0.12.5 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.