Bug 1888248 (CVE-2020-15157)
Summary: | CVE-2020-15157 containerd: credentials leak during image pull | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | msiddiqu |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | adam.kaplan, agarcial, amasferr, aos-bugs, bmontgom, chazlett, cnv-qe-bugs, ecordell, eparis, fdeutsch, gghezzo, go-sig, gparvin, jburrell, jhadvig, jlanford, jokerman, jramanat, jweiser, kconner, maszulik, mfojtik, nstielau, obulatov, o.lemasle, phoracek, rcernich, security-response-team, sponnaga, stcannon, sttts, thee, wzheng, xxia |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | containerd 1.2.14, containerd 1.3.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in containerd. Credentials may be leaked during an image pull.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-02-24 19:01:59 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1890518, 1890519, 1890520, 1890620 | ||
Bug Blocks: | 1888277 |
Description
msiddiqu
2020-10-14 13:29:55 UTC
References: https://www.openwall.com/lists/oss-security/2020/10/15/1 https://github.com/containerd/containerd/security/advisories/GHSA-742w-89gc-8m9c https://github.com/containerd/containerd/releases/tag/v1.2.14 External References: https://github.com/containerd/containerd/security/advisories/GHSA-742w-89gc-8m9c https://github.com/containerd/containerd/releases/tag/v1.2.14 https://www.openwall.com/lists/oss-security/2020/10/15/1 Upstream commit with fix: https://github.com/containerd/containerd/commit/1ead8d9deb3b175bf40413b8c47b3d19c2262726 Statement: In OpenShift Container Platform (OCP) the ose-cluster-autoscaler container ships vulnerable version of the containerd package, but only containerd api is used by the container. The vulnerable code is not delivered, hence marked as wontfix. Created containerd tracking bugs for this issue: Affects: epel-7 [bug 1890620] Acknowledgments: Name: The containerd project Upstream: Brad Geesaman, Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2020:5634 https://access.redhat.com/errata/RHSA-2020:5634 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-15157 |