VDB
Sign up
HIGH8.3

GHSA-6wvf-f2vw-3425

github.com/containers/image allows unexpected authenticated registry accesses

Quick fix

GHSA-6wvf-f2vw-3425 — github.com/containers/image: upgrade to the fixed version with the command below.

go get github.com/containers/image@v5.30.1

Details

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/containers/image
Introduced in: 0Fixed in: 5.30.1
Fixgo get github.com/containers/image@v5.30.1
Go/github.com/containers/image/v5
Introduced in: 5.30.0Fixed in: 5.30.1
Fixgo get github.com/containers/image/v5@v5.30.1
Go/github.com/containers/image/v5
Introduced in: 0Fixed in: 5.29.3
Fixgo get github.com/containers/image/v5@v5.29.3

References