[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-41190Date: (C)2021-11-19   (M)2023-12-22


The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both ���manifests��� and ���layers��� fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both ���manifests��� and ���layers��� fields or ���manifests��� and ���config��� fields if they are unable to update to version 1.0.1 of the spec.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.0CVSS Score : 4.0
Exploit Score: 3.1Exploit Score: 8.0
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: NONE
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: LOW 
Availability: NONE 
  
Reference:
FEDORA-2021-3dda301691
FEDORA-2021-62352983b4
FEDORA-2021-6789ed60f2
FEDORA-2021-6dc68dbe4d
FEDORA-2021-79ba5abef6
FEDORA-2021-aacef7fa15
FEDORA-2021-d250fc2622
FEDORA-2021-eb2742b148
http://www.openwall.com/lists/oss-security/2021/11/19/10
https://github.com/opencontainers/distribution-spec/commit/ac28cac0557bcd3084714ab09f9f2356fe504923
https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m

CWE    1
CWE-843
OVAL    23
oval:org.secpod.oval:def:507303
oval:org.secpod.oval:def:3300322
oval:org.secpod.oval:def:1506184
oval:org.secpod.oval:def:1601499
...

© SecPod Technologies