Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2h62-wf4g-8rpr

Опубликовано: 29 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.3

Описание

Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down unapproved, and potentially malicious images from any registry.

Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down unapproved, and potentially malicious images from any registry.

EPSS

Процентиль: 7%
0.00027
Низкий

4.3 Medium

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
9 месяцев назад

Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down unapproved, and potentially malicious images from any registry.

EPSS

Процентиль: 7%
0.00027
Низкий

4.3 Medium

CVSS4

Дефекты

CWE-862