Описание
In regclient, pinned manifest digests may be ignored
Impact
A malicious registry could return a different digest for a pinned manifest without detection.
Patches
This has been fixed in the v0.7.1 release.
Workarounds
After running a regclient.ManifestGet, the returned digest can be compared to the requested digest.
Пакеты
github.com/regclient/regclient
< 0.7.1
0.7.1
EPSS
5.8 Medium
CVSS4
5.2 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
regclient is a Docker and OCI Registry Client in Go. A malicious regis ...
EPSS
5.8 Medium
CVSS4
5.2 Medium
CVSS3