## Embedded cache registry binds to all interfaces with no authentication
**CWEs:** CWE-306, CWE-668
**CVSS:** 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N)
**Component:** openshift-4.21-payload/oc-mirror__release-4.21
### Description
setupLocalRegistryConfig() renders a distribution/v3 registry configuration whose HTTP listener is `addr: :{{ .LocalStoragePort }}` (default 55000). Because no host is specified the Go net/http stack binds 0.0.0.0/[::]. The htpasswd auth block is commented out, delete is enabled, and TLS is not configured. The registry is started via LocalStorageService.ListenAndServe() for the full duration of mirrorToDisk / diskToMirror runs, which on large payloads can be hours. The separate isLocalStoragePortBound() probe dials `localhost:%d`, masking the fact that the actual server is not loopback-restricted.
### Affected Locations
- `:`
- `:`
- `:`
### Evidence
**internal/pkg/cli/executor.go:640-648 — registry config template binds to ':<port>' with auth commented out**
```go
http:
addr: :{{ .LocalStoragePort }}
headers:
X-Content-Type-Options: [nosniff]
#auth:
#htpasswd:
#realm: basic-realm
#path: /etc/registry
```
### Attack Pattern
Adjacent-network host → push tampered image blobs into the operator's local cache registry, or pull mirrored Red Hat content, while oc-mirror is running.
---
*Source: Ex-Wing security assessment, finding FIND-001*
## Embedded cache registry binds to all interfaces with no authentication **CWEs:** CWE-306, CWE-668 **CVSS:** 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N) **Component:** openshift-4.21-payload/oc-mirror__release-4.21 ### Description setupLocalRegistryConfig() renders a distribution/v3 registry configuration whose HTTP listener is `addr: :{{ .LocalStoragePort }}` (default 55000). Because no host is specified the Go net/http stack binds 0.0.0.0/[::]. The htpasswd auth block is commented out, delete is enabled, and TLS is not configured. The registry is started via LocalStorageService.ListenAndServe() for the full duration of mirrorToDisk / diskToMirror runs, which on large payloads can be hours. The separate isLocalStoragePortBound() probe dials `localhost:%d`, masking the fact that the actual server is not loopback-restricted. ### Affected Locations - `:` - `:` - `:` ### Evidence **internal/pkg/cli/executor.go:640-648 — registry config template binds to ':<port>' with auth commented out** ```go http: addr: :{{ .LocalStoragePort }} headers: X-Content-Type-Options: [nosniff] #auth: #htpasswd: #realm: basic-realm #path: /etc/registry ``` ### Attack Pattern Adjacent-network host → push tampered image blobs into the operator's local cache registry, or pull mirrored Red Hat content, while oc-mirror is running. --- *Source: Ex-Wing security assessment, finding FIND-001*