Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
oras-go: credential forwarding via unvalidated Location header in blob upload
Vulnerability Description
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
oras-project oras-go 服务端请求伪造漏洞
Vulnerability Description
oras-project oras-go是oras-project组织的一个基于OCI标准的内容分发库软件。 oras-project oras-go 2.6.1之前版本存在服务端请求伪造漏洞,该漏洞源于在monolithic blob上传过程中跟随registry控制的Location标头并重用Authorization标头,可能导致恶意registry返回跨主机Location并在攻击者控制的端点接收调用者凭据。
CVSS Information
N/A
Vulnerability Type
N/A