In regclient, pinned manifest digests may be ignored
Moderate severity
GitHub Reviewed
Published
Aug 3, 2024
in
regclient/regclient
•
Updated Aug 7, 2024
Description
Published to the GitHub Advisory Database
Aug 5, 2024
Reviewed
Aug 5, 2024
Last updated
Aug 7, 2024
Impact
A malicious registry could return a different digest for a pinned manifest without detection.
Patches
This has been fixed in the v0.7.1 release.
Workarounds
After running a
regclient.ManifestGet
, the returned digest can be compared to the requested digest.References