Vulnerability in Containerd Can Leak Cloud Credential
ID: 8210883e-54a9-5160-813c-473a2c1e8f2d
STIX ID: report--8210883e-54a9-5160-813c-473a2c1e8f2d
Feed Name: Aqua Security Blog
A vulnerability in containerd's image-pulling process (documented as "ContainerDrip") allows an attacker-controlled image manifest containing a foreign layer URL to provoke an HTTP 401 authentication challenge from a remote host; containerd may then send host authentication tokens (e.g., GCP service account OAuth tokens) to that remote endpoint before any image code runs, enabling credential theft and potential cloud project takeover. The issue was demonstrated in a simulated GKE/GCR scenario and has been patched in containerd 1.2.14 (and validated fixed in 1.3.x).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
