CVE-2020-15157Insufficiently Protected Credentials in Containerd

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 26.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateAug 21

Description

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x but not 1.3.0 or later, the default containerd resolver will provide its authentication credentials i

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 1.6 | Impact: 4.0

Affected Packages4 packages

CVEListV5containerd/containerd< 1.2.14
NVDlinuxfoundation/containerd1.2.01.2.14+1
Debiancontainerd/containerd< 1.3.2~ds1-2+3

Also affects: Debian Linux 10.0, Ubuntu Linux 16.04, 18.04, 20.04

🔴Vulnerability Details

5
OSV
containerd v1.2.x can be coerced into leaking credentials during image pull in github.com/containerd/containerd2024-08-21
GHSA
containerd v1.2.x can be coerced into leaking credentials during image pull2022-02-11
OSV
containerd v1.2.x can be coerced into leaking credentials during image pull2022-02-11
CVEList
containerd can be coerced into leaking credentials during image pull2020-10-16
OSV
CVE-2020-15157: In containerd (an industry-standard container runtime) before version 12020-10-16

📋Vendor Advisories

4
Red Hat
containerd: credentials leak during image pull2020-10-15
Ubuntu
containerd vulnerability2020-10-15
Ubuntu
Docker vulnerability2020-10-15
Debian
CVE-2020-15157: containerd - In containerd (an industry-standard container runtime) before version 1.2.14 the...2020

💬Community

2
Bugzilla
CVE-2020-15157 containerd: credentials leak during image pull [epel-7]2020-10-22
Bugzilla
CVE-2020-15157 containerd: credentials leak during image pull2020-10-14
CVE-2020-15157 — Insufficiently Protected Credentials | cvebase