CWE
843
Advisory Published
CVE Published
Updated

CVE-2021-41190: Clarify Content-Type handling in OCI spec

First published: Wed Nov 17 2021(Updated: )

In the OCI Distribution Specification version 1.0.0 and prior and in the OCI Image Specification version 1.0.1 and prior, manifest and index documents are ambiguous without an accompanying Content-Type HTTP header. Versions of Moby (Docker Engine) prior to 20.10.11 treat the Content-Type header as trusted and deserialize the document according to that header. If the Content-Type header changed between pulls of the same ambiguous document (with the same digest), the document may be interpreted differently, meaning that the digest alone is insufficient to unambiguously identify the content of the image. References: <a href="https://github.com/moby/moby/security/advisories/GHSA-xmmx-7jpf-fx42">https://github.com/moby/moby/security/advisories/GHSA-xmmx-7jpf-fx42</a> <a href="https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m">https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m</a> <a href="https://github.com/opencontainers/image-spec/security/advisories/GHSA-77vh-xpmg-72qh">https://github.com/opencontainers/image-spec/security/advisories/GHSA-77vh-xpmg-72qh</a> <a href="https://github.com/containerd/containerd/releases/tag/v1.4.12">https://github.com/containerd/containerd/releases/tag/v1.4.12</a> <a href="https://github.com/containerd/containerd/releases/tag/v1.5.8">https://github.com/containerd/containerd/releases/tag/v1.5.8</a> <a href="https://github.com/moby/moby/releases/tag/v20.10.11">https://github.com/moby/moby/releases/tag/v20.10.11</a> <a href="https://github.com/containerd/containerd/security/advisories/GHSA-5j5w-g665-5m35">https://github.com/containerd/containerd/security/advisories/GHSA-5j5w-g665-5m35</a>

Credit: security-advisories@github.com security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
redhat/cri-o<0:1.23.0-92.rhaos4.10.gitdaab4d1.el7
0:1.23.0-92.rhaos4.10.gitdaab4d1.el7
Linuxfoundation Open Container Initiative Distribution Specification<=1.0.0
Linuxfoundation Open Container Initiative Image Format Specification<=1.0.1
Fedoraproject Fedora=34
Fedoraproject Fedora=35
redhat/opencontainers/image-spec<1.0.1
1.0.1
<=1.0.0
<=1.0.1
=34
=35

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203