Fedora Account System
Red Hat Associate
Red Hat Customer
## Embedded cache registry binds to all interfaces with no authentication **CWEs:** CWE-306, CWE-668 **CVSS:** 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N) **Component:** openshift-4.21-payload/oc-mirror__release-4.21 ### Description setupLocalRegistryConfig() renders a distribution/v3 registry configuration whose HTTP listener is `addr: :{{ .LocalStoragePort }}` (default 55000). Because no host is specified the Go net/http stack binds 0.0.0.0/[::]. The htpasswd auth block is commented out, delete is enabled, and TLS is not configured. The registry is started via LocalStorageService.ListenAndServe() for the full duration of mirrorToDisk / diskToMirror runs, which on large payloads can be hours. The separate isLocalStoragePortBound() probe dials `localhost:%d`, masking the fact that the actual server is not loopback-restricted. ### Affected Locations - `:` - `:` - `:` ### Evidence **internal/pkg/cli/executor.go:640-648 — registry config template binds to ':<port>' with auth commented out** ```go http: addr: :{{ .LocalStoragePort }} headers: X-Content-Type-Options: [nosniff] #auth: #htpasswd: #realm: basic-realm #path: /etc/registry ``` ### Attack Pattern Adjacent-network host → push tampered image blobs into the operator's local cache registry, or pull mirrored Red Hat content, while oc-mirror is running. --- *Source: Ex-Wing security assessment, finding FIND-001*