Lucene search

K
osvGoogleOSV:USN-4589-2
HistoryOct 15, 2020 - 8:00 p.m.

docker.io vulnerability

2020-10-1520:00:45
Google
osv.dev
7

9.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.3%

USN-4589-1 fixed a vulnerability in containerd. This update provides
the corresponding update for docker.io.

Original advisory details:

It was discovered that containerd could be made to expose sensitive
information when processing URLs in container image manifests. A
remote attacker could use this to trick the user and obtain the
user’s registry credentials.