Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33540

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.

A flaw was found in Distribution, a toolkit for managing container content. When operating in pull-through cache mode, Distribution incorrectly processes authentication challenges from an upstream registry. An attacker controlling the upstream registry, or positioned as a Man-in-the-Middle (MitM), can exploit this by providing a malicious authentication realm URL. This vulnerability can cause Distribution to send sensitive upstream credentials, via basic authentication, to an attacker-controlled server, leading to information disclosure.

Меры по смягчению последствий

To mitigate this issue, ensure that all upstream registries configured for Distribution in pull-through cache mode are trusted and secured. Implement network segmentation and firewall rules to restrict outbound connections from the Distribution instance to only known and trusted upstream registry endpoints. This reduces the risk of an attacker-controlled upstream or a Man-in-the-Middle attack redirecting authentication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift3/ose-operator-lifecycle-managerFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-framework-tools-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-lifecycle-managerFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-lifecycle-manager-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-registryFix deferred
Red Hat OpenShift Container Platform 4redhat/redhat-operator-indexFix deferred
Red Hat Openshift Data Foundation 4.22odf4/cephcsi-rhel9FixedRHSA-2026:3738709.07.2026
Red Hat Openshift Data Foundation 4.22odf4/cephcsi-rhel9-operatorFixedRHSA-2026:3738709.07.2026
Red Hat Openshift Data Foundation 4.22odf4/devicefinder-rhel9FixedRHSA-2026:3738709.07.2026
Red Hat Openshift Data Foundation 4.22odf4/mcg-core-rhel9FixedRHSA-2026:3738709.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2455430github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL

EPSS

Процентиль: 19%
0.00274
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
nvd
4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating that it matches the upstream registry host. As a result, an attacker-controlled upstream (or an attacker with MitM position to the upstream) can cause distribution to send the configured upstream credentials via basic auth to an attacker-controlled realm URL. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
debian
4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container ...

CVSS3: 7.5
github
4 месяца назад

Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 19%
0.00274
Низкий

3.1 Low

CVSS3