Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-59891

около 1 месяца назад

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an exact host match, credentials configured for one registry can be selected for and transmitted to a different registry whose hostname has a substring relationship with a configured auth key. This issue is fixed in version 0.7.1.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-pf56-329r-95rw

около 1 месяца назад

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-59891

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an exact host match, credentials configured for one registry can be selected for and transmitted to a different registry whose hostname has a substring relationship with a configured auth key. This issue is fixed in version 0.7.1.

CVSS3: 9.6
0%
Низкий
около 1 месяца назад
github логотип
GHSA-pf56-329r-95rw

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

CVSS3: 9.6
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу