Описание
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.
A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attacker-controlled endpoint to receive the caller's credentials, leading to information disclosure. Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target.
Отчет
A flaw was found in oras-go. During monolithic blob upload, the Authorization header is reused for cross-host Location redirects, allowing a malicious registry to exfiltrate caller credentials.
Меры по смягчению последствий
Upgrade to oras-go v2.6.1 or later.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Under investigation | ||
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Under investigation | ||
| OpenShift Service Mesh 3 | openshift-service-mesh/istio-rhel9-operator | Under investigation | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel9 | Affected | ||
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-rhel9-operator | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/cnf-tests-rhel8 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift4/metallb-rhel8-operator | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift4/metallb-rhel9-operator | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel8 | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel9 | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
EPSS
5.9 Medium
CVSS3