In regclient, pinned manifest digests may be ignored
Moderate severity
GitHub Reviewed
Published
Aug 3, 2024
in
regclient/regclient
•
Updated Jan 29, 2025
Description
Published to the GitHub Advisory Database
Aug 5, 2024
Reviewed
Aug 5, 2024
Published by the National Vulnerability Database
Jan 29, 2025
Last updated
Jan 29, 2025
Impact
A malicious registry could return a different digest for a pinned manifest without detection.
Patches
This has been fixed in the v0.7.1 release.
Workarounds
After running a
regclient.ManifestGet
, the returned digest can be compared to the requested digest.References