Lucene search

K
osvGoogleOSV:GO-2021-0081
HistoryApr 14, 2021 - 8:04 p.m.

Insufficiently Protected Credentials in github.com/containers/image

2021-04-1420:04:52
Google
osv.dev
22

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%

The HTTP client used to connect to the container registry authorization service explicitly disables TLS verification, allowing an attacker that is able to MITM the connection to steal credentials.