Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85p9-j7c9-v4gr

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

containers/image library Insufficiently Protects Credentials

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

Пакеты

Наименование

github.com/containers/image

go
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 48%
0.00246
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 5 лет назад

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS3: 6.4
redhat
почти 6 лет назад

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS3: 5.9
nvd
больше 5 лет назад

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS3: 5.9
debian
больше 5 лет назад

The containers/image library used by the container tools Podman, Build ...

suse-cvrf
около 5 лет назад

Security update for skopeo

EPSS

Процентиль: 48%
0.00246
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-522