Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-f2g3-hh2r-cwgc

4 месяца назад

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-35172

4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-35172

4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-35172

4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-35172

4 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07552

4 месяца назад

Уязвимость функции распространения инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с ошибками разграничения доступа, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260526-73-0015

2 месяца назад

Уязвимость registry

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20686-1

3 месяца назад

Security update for distribution

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f2g3-hh2r-cwgc

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

CVSS3: 7.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-35172

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-35172

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-35172

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-35172

Distribution is a toolkit to pack, ship, store, and deliver container ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07552

Уязвимость функции распространения инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с ошибками разграничения доступа, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.5
0%
Низкий
4 месяца назад
redos логотип
ROS-20260526-73-0015

Уязвимость registry

CVSS3: 7.5
0%
Низкий
2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20686-1

Security update for distribution

3 месяца назад

Уязвимостей на страницу