Impact
A remote attacker who controls a container registry can redirect a client’s token request to a server chosen by the attacker. This causes the client to send its registry credentials to the attacker’s host, enabling the attacker to obtain the victim’s authenticators and potentially access the registry or other protected resources. The flaw is an insecure redirect vulnerability and is classified as CWE-601.
Affected Systems
The vulnerability affects Apple containerization implementations prior to version 0.41.0. Any deployment of Apple containerization that allows a client to contact a registry that can be manipulated by an attacker is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attacker must be able to control or influence the registry endpoint the client contacts, which typically requires remote access to the registry configuration or hosting environment. Successful exploitation would grant an attacker the victim’s registry credentials, leading to credential compromise and potential lateral movement.
OpenCVE Enrichment