Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15157

Опубликовано: 16 окт. 2020
Источник: nvd
CVSS3: 6.1
CVSS2: 2.6
EPSS Низкий

Описание

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x but not 1.3.0 or later, the default containerd resolver will provide its authentication credentials if the server where the URL is located presents an HTTP 401 status code along with registry-specific HTTP headers. If an attacker publishes a public image with a manifest that directs one of the layers to be fetched from a web server they control and they trick a user or system into pulling the image, they can obtain the credentials used for pulling that image. In some cases, this may be the user's username and password for the registry. In other cases, this may be the credentials attached to

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
Версия от 1.2.0 (включая) до 1.2.14 (исключая)
cpe:2.3:a:linuxfoundation:containerd:1.3.0:-:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:beta0:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:rc0:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:1.3.0:rc3:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.0137
Низкий

6.1 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-522
CWE-522

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x but not 1.3.0 or later, the default containerd resolver will provide its authentication credentials if the server where the URL is located presents an HTTP 401 status code along with registry-specific HTTP headers. If an attacker publishes a public image with a manifest that directs one of the layers to be fetched from a web server they control and they trick a user or system into pulling the image, they can obtain the credentials used for pulling that image. In some cases, this may be the user's username and password for the registry. In other cases, this may be the credentials attached...

CVSS3: 6.1
redhat
больше 5 лет назад

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x but not 1.3.0 or later, the default containerd resolver will provide its authentication credentials if the server where the URL is located presents an HTTP 401 status code along with registry-specific HTTP headers. If an attacker publishes a public image with a manifest that directs one of the layers to be fetched from a web server they control and they trick a user or system into pulling the image, they can obtain the credentials used for pulling that image. In some cases, this may be the user's username and password for the registry. In other cases, this may be the credentials attached...

CVSS3: 6.1
debian
больше 5 лет назад

In containerd (an industry-standard container runtime) before version ...

CVSS3: 6.1
github
почти 4 года назад

containerd v1.2.x can be coerced into leaking credentials during image pull

oracle-oval
больше 5 лет назад

ELSA-2020-5906: containerd security update (IMPORTANT)

EPSS

Процентиль: 80%
0.0137
Низкий

6.1 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-522
CWE-522