Database/Control plane, storage & DevOps
Renovate: Docker datasource follows cross-origin Link pagination and sends registry credentials to the attacker's host
Impact
When Renovate lists tags or digests for a container image it follows the registry's HTTP Link header to the next page and re-attaches the configured registry credentials without checking that the next URL is the same origin. A malicious or compromised registry can therefore redirect the credentialed request to a host of its choosing. Those are usually pull - and sometimes push - credentials for the registry that holds your CUDA base images, model-serving images and internal training images; a leaked push credential is an image-supply-chain problem for every GPU node that pulls from it. Renovate runs self-hosted in many clusters (CE/EE images and Helm charts), so this is a bot on your control plane handing out its own secrets. Exploitation requires that Renovate already talks to the bad registry, which it did on the initial request too - the new capability is delivering the credentials to an additional, attacker-chosen host.
Who can reach it
An operator of a container registry that your Renovate instance is already configured to query, or anyone who has compromised one. No access to your cluster or authentication against it is needed - only control of a registry response.
What to do
Upgrade to Renovate 44.11.2 (npm package or renovate/renovate image), Mend Renovate CE/EE 15.4.0, or mend-renovate-enterprise-edition Helm chart 10.4.0, then redeploy the bot - a pod or daemon restart, no node work. Do not set RENOVATE_X_DOCKER_PAGINATION_ALLOW_CROSS_ORIGIN, which restores the vulnerable behaviour. Rotate registry credentials that Renovate held if you use third-party or shared registries.
References
Related entries
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCVE-2018-6440 · Brocade Fabric OS (proxy service information disclosure)Critical
- IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCVE-2020-4926 · IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1Critical
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCVE-2021-1577 · Cisco APIC / Cloud APIC (API endpoint)Critical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCVE-2021-22794 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the networkCVE-2021-22795 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.