Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-24976

Опубликовано: 11 фев. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an untrusted signing key in a JSON web token (JWT). The issue lies in how the JSON web key (JWK) verification is performed. When a JWT contains a JWK header without a certificate chain, the code only checks if the KeyID (kid) matches one of the trusted keys, but doesn't verify that the actual key material matches. A fix for the issue is available at commit 5ea9aa028db65ca5665f6af2c20ecf9dc34e5fcd and expected to be a part of version 3.0.0-rc.3. There is no way to work around this issue without patching if the system requires token authentication.

A flaw was found in Distribution. Certain versions with token authentication enabled may be vulnerable to an issue where token authentication allows an attacker to inject an untrusted signing key in a JSON web token (JWT). The issue is due to how the JSON web key (JWK) verification is performed. When a JWT contains a JWK header without a certificate chain, the code only checks if the KeyID (kid) matches one of the trusted keys but doesn't verify that the key material matches.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multiarch Tuning Operatormultiarch-tuning/multiarch-tuning-rhel9-operatorWill not fix
OpenShift API for Data Protectionoadp/oadp-velero-plugin-rhel9Fix deferred
OpenShift Serverlessopenshift-serverless-1/serverless-ingress-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/serverless-kn-operator-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/serverless-must-gather-rhel8Will not fix
OpenShift Serverlessopenshift-serverless-1/serverless-openshift-kn-rhel8-operatorWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel8Fix deferred
Red Hat OpenShift Container Platform 4microshiftNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-cliNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-cli-artifacts-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2344940distribution: Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT

EPSS

Процентиль: 27%
0.00347
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

nvd
больше 1 года назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an untrusted signing key in a JSON web token (JWT). The issue lies in how the JSON web key (JWK) verification is performed. When a JWT contains a JWK header without a certificate chain, the code only checks if the KeyID (`kid`) matches one of the trusted keys, but doesn't verify that the actual key material matches. A fix for the issue is available at commit 5ea9aa028db65ca5665f6af2c20ecf9dc34e5fcd and expected to be a part of version 3.0.0-rc.3. There is no way to work around this issue without patching if the system requires token authentication.

debian
больше 1 года назад

Distribution is a toolkit to pack, ship, store, and deliver container ...

EPSS

Процентиль: 27%
0.00347
Низкий

6.5 Medium

CVSS3