Medium severity6.1NVD Advisory· Published Mar 19, 2024· Updated Apr 15, 2026
CVE-2024-2307
CVE-2024-2307
Description
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.