Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-41190
HistoryNov 17, 2021 - 7:20 p.m.

CVE-2021-41190 Clarify Content-Type handling in OCI spec

2021-11-1719:20:11
CWE-843
GitHub_M
www.cve.org
8
cve-2021-41190
oci distribution spec
content-type handling
manifest
layers
index
mediatype
push
pull
update

CVSS3

3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

48.7%

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both “manifests” and “layers” fields or “manifests” and “config” fields if they are unable to update to version 1.0.1 of the spec.

CNA Affected

[
  {
    "product": "distribution-spec",
    "vendor": "opencontainers",
    "versions": [
      {
        "status": "affected",
        "version": "< 1.0.1"
      }
    ]
  }
]

References

CVSS3

3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

48.7%