Database/Container, Kubernetes & orchestration
containerd: "ContainerDrip": registry credentials leaked to an attacker-controlled URL referenced in an image manifest
CVE-2020-15157Container, Kubernetes & orchestrationcurated
Impact
"ContainerDrip": registry credentials leaked to an attacker-controlled URL referenced in an image manifest
Who can reach it
Malicious image pulled from an untrusted registry
What to do
Upgrade containerd; rotate any registry pull credentials that may have leaked
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.