Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-41190


The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both “manifests” and “layers” fields or “manifests” and “config” fields if they are unable to update to version 1.0.1 of the spec.


Published

2021-11-17T20:15:10.333

Last Modified

2024-11-21T06:25:43.537

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.0 (LOW)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-843
  • Type: Primary
    CWE-843

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application linuxfoundation open_container_initiative_distribution_specification ≤ 1.0.0 Yes
Application linuxfoundation open_container_initiative_image_format_specification ≤ 1.0.1 Yes
Operating System fedoraproject fedora 34 Yes
Operating System fedoraproject fedora 35 Yes

References