Описание
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.
A flaw was found in oras-go. The auth.Client in oras-go does not properly validate the scheme or host of the realm URL provided in a registry's WWW-Authenticate: Bearer challenge. A remote attacker, operating a malicious registry or performing a man-in-the-middle attack, could exploit this to perform Server-Side Request Forgery (SSRF) against internal networks, potentially disclosing sensitive information. Additionally, the flaw could lead to a Transport Layer Security (TLS) downgrade, causing user credentials to be sent over plaintext.
Отчет
A flaw was found in oras-go. The auth.Client follows the realm URL from a registry's Bearer challenge without validating scheme or host, enabling SSRF to internal networks and TLS downgrade attacks.
Меры по смягчению последствий
Upgrade to oras-go v2.6.1 or later.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Fix deferred | ||
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fix deferred | ||
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-rhel9-operator | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/cnf-tests-rhel8 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/metallb-rhel8-operator | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/metallb-rhel9-operator | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel8 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-ansible-operator | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-azure-cluster-api-controllers-rhel8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
(oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
EPSS
3.1 Low
CVSS3