logo

Vulnerability in Containerd Can Leak Cloud Credential

ID: 8210883e-54a9-5160-813c-473a2c1e8f2d

STIX ID: report--8210883e-54a9-5160-813c-473a2c1e8f2d

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2020-10-22

Date Updated: 2026-04-26

...
...

A vulnerability in containerd's image-pulling process (documented as "ContainerDrip") allows an attacker-controlled image manifest containing a foreign layer URL to provoke an HTTP 401 authentication challenge from a remote host; containerd may then send host authentication tokens (e.g., GCP service account OAuth tokens) to that remote endpoint before any image code runs, enabling credential theft and potential cloud project takeover. The issue was demonstrated in a simulated GKE/GCR scenario and has been patched in containerd 1.2.14 (and validated fixed in 1.3.x).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.