Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
This fixes CVE-2024-3727 . Digest values used throughout this library were not always validated. That allowed attackers to trigger, when pulling untrusted images, unexpected authenticated registry accesses on behalf of a victim user. In less common uses of this library (using other transports or not using the containers/image/v5/copy.Image API), an attacker could also trigger local path traversals or crashes. Signed-off-by: Miloslav Trmač <mitr@redhat.com>
- Loading branch information