Database/Container, Kubernetes & orchestration
OCI Distribution Spec: Content-Type alone determines manifest type, so a manifest can be interpreted differently
CVSS 3.0CVE-2021-41190Container, Kubernetes & orchestrationcurated
Impact
Content-Type alone determines manifest type, so a manifest can be interpreted differently by different clients; signature and policy confusion
Who can reach it
Malicious image in any registry
What to do
Upgrade registry and client tooling; pin by digest rather than tag
References
Related entries
- containerd (OCI manifest / index parsing, Content-Type handling): SUPPLY CHAIN: the image digest stops being anNCVD-2021-013-containerd-oci-manifest-index-pa · containerd (OCI manifest / index parsing, Content-Type handling)Low
- Docker / moby: `docker cp` into a crafted container changes Unix permissions of existing host filesCVE-2021-41089 · Docker / mobyLow
- Argo Workflows Helm chart (argo-helm, workflow-role privileges on workflowtasksets / workflowartifactgctasks): TheCVE-2024-52814 · Argo Workflows Helm chart (argo-helm, workflow-role privileges on workflowtasksets / workflowartifactgctasks)Low
- Kubernetes: Endpoint IPs can redirect pod traffic to private node networksCVE-2021-25737 · KubernetesLow
- Kubernetes (kube-apiserver): Init/ephemeral container envFrom bypasses the ServiceAccount mountable-secrets policyCVE-2024-3177 · Kubernetes (kube-apiserver)Low
- Kubernetes (kube-apiserver): Nodes can bypass DRA authorization checksCVE-2025-4563 · Kubernetes (kube-apiserver)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.