—
GO-2022-0803
containerd v1.2.x can be coerced into leaking credentials during image pull in github.com/containerd/containerd
Quick fix
GO-2022-0803 — github.com/containerd/containerd: upgrade to the fixed version with the command below.
go get github.com/containerd/containerd@v1.2.14Details
containerd v1.2.x can be coerced into leaking credentials during image pull in github.com/containerd/containerd
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/containerd/containerd
Introduced in:
0Fixed in: 1.2.14Fix
go get github.com/containerd/containerd@v1.2.14References
- https://github.com/containerd/containerd/security/advisories/GHSA-742w-89gc-8m9c[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2020-15157[ADVISORY]
- https://github.com/containerd/containerd/commit/1ead8d9deb3b175bf40413b8c47b3d19c2262726[FIX]
- https://github.com/containerd/containerd/releases/tag/v1.2.14[WEB]
- https://usn.ubuntu.com/4589-1[WEB]
- https://usn.ubuntu.com/4589-2[WEB]
- https://www.debian.org/security/2021/dsa-4865[WEB]