CVE Database
/

CVE-2021-41190

Back to search

CVE-2021-41190

Published: Nov 17, 2021

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

3.0

LOW

Description

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both “manifests” and “layers” fields or “manifests” and “config” fields if they are unable to update to version 1.0.1 of the spec.

VendorProductVersions

opencontainers

distribution-spec

affected
< 1.0.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

References

FEDORA-2021-d250fc2622
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-6dc68dbe4d
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-79ba5abef6
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-eb2742b148
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-3dda301691
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-aacef7fa15
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-62352983b4
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-6789ed60f2
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now