Описание
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.
A flaw was found in Distribution, a toolkit for managing container content. When operating in pull-through cache mode, Distribution incorrectly processes authentication challenges from an upstream registry. An attacker controlling the upstream registry, or positioned as a Man-in-the-Middle (MitM), can exploit this by providing a malicious authentication realm URL. This vulnerability can cause Distribution to send sensitive upstream credentials, via basic authentication, to an attacker-controlled server, leading to information disclosure.
Меры по смягчению последствий
To mitigate this issue, ensure that all upstream registries configured for Distribution in pull-through cache mode are trusted and secured. Implement network segmentation and firewall rules to restrict outbound connections from the Distribution instance to only known and trusted upstream registry endpoints. This reduces the risk of an attacker-controlled upstream or a Man-in-the-Middle attack redirecting authentication.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift3/ose-operator-lifecycle-manager | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-framework-tools-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-lifecycle-manager | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-lifecycle-manager-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-registry | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | redhat/redhat-operator-index | Fix deferred | ||
| Red Hat Openshift Data Foundation 4.22 | odf4/cephcsi-rhel9 | Fixed | RHSA-2026:37387 | 09.07.2026 |
| Red Hat Openshift Data Foundation 4.22 | odf4/cephcsi-rhel9-operator | Fixed | RHSA-2026:37387 | 09.07.2026 |
| Red Hat Openshift Data Foundation 4.22 | odf4/devicefinder-rhel9 | Fixed | RHSA-2026:37387 | 09.07.2026 |
| Red Hat Openshift Data Foundation 4.22 | odf4/mcg-core-rhel9 | Fixed | RHSA-2026:37387 | 09.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.
Distribution is a toolkit to pack, ship, store, and deliver container ...
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
Уязвимость инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку
EPSS
3.1 Low
CVSS3